Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hxm-qqg6-q8f9

Опубликовано: 11 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213463.

A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213463.

EPSS

Процентиль: 13%
0.00045
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-401
CWE-404

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213463.

CVSS3: 4.3
nvd
больше 2 лет назад

A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_preserveaspectratio of the file scenegraph/svg_attributes.c of the component SVG Parser. The manipulation leads to memory leak. The attack can be launched remotely. The name of the patch is 2191e66aa7df750e8ef01781b1930bea87b713bb. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-213463.

CVSS3: 4.3
debian
больше 2 лет назад

A vulnerability classified as problematic was found in GPAC. Affected ...

CVSS3: 6.5
redos
больше 2 лет назад

Уязвимость GPAC

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость функции svg_parse_preserveaspectratio() компонента SVG Parser мультимедийной платформы GPAC, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 13%
0.00045
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-401
CWE-404