Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcqp-688w-crp9

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 0.9
CVSS3: 2.8

Описание

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.

EPSS

Процентиль: 1%
0.00111
Низкий

0.9 Low

CVSS4

2.8 Low

CVSS3

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 2.8
ubuntu
3 дня назад

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.

CVSS3: 2.8
nvd
3 дня назад

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.

CVSS3: 2.8
debian
3 дня назад

A flaw has been found in GPAC up to f1219cde. Affected by this vulnera ...

EPSS

Процентиль: 1%
0.00111
Низкий

0.9 Low

CVSS4

2.8 Low

CVSS3

Дефекты

CWE-617