CVE Vulnerabilities

CVE-2023-46427

NULL Pointer Dereference

Published: Mar 09, 2024 | Modified: Sep 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_period component in media_tools/dash_client.c.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Gpac Gpac 2.3-dev-rev588-g7edc40fee-master (including) 2.3-dev-rev588-g7edc40fee-master (including)
Gpac Ubuntu focal *
Gpac Ubuntu trusty/esm *

Potential Mitigations

References