CVE Vulnerabilities

CVE-2023-46427

NULL Pointer Dereference

Published: Mar 09, 2024 | Modified: Sep 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_period component in media_tools/dash_client.c.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
GpacGpac2.3-dev-rev588-g7edc40fee-master (including)2.3-dev-rev588-g7edc40fee-master (including)
GpacUbuntufocal*
GpacUbuntutrusty/esm*

Potential Mitigations

References