GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://github.com/gpac/gpac/issues/2658 | patch exploit third party advisory issue tracking |
https://gist.github.com/ReturnHere/d0899bb03b8f5e8fae118f2b76888486 | third party advisory exploit |