A vulnerability, which was classified as critical, has been found in GPAC 2.3-DEV-rev40-g3602a5ded. This issue affects the function mp3dmxprocess of the file filters/reframe_mp3.c. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-221087.
[
{
"signature_type": "Line",
"target": {
"file": "src/filters/reframe_mp3.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/851560e3dc8155d45ace4b0d77421f241ed71dc4",
"id": "CVE-2023-0841-3f722ece",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"91027400660819814565648575534343067138",
"204861493937783127057110627732198068679",
"262767585465499177028051232110547367350",
"215017295332380655085818416976670673391",
"66034433443152882404025193101270035272"
]
}
},
{
"signature_type": "Function",
"target": {
"file": "src/filters/reframe_mp3.c",
"function": "mp3_dmx_process"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/851560e3dc8155d45ace4b0d77421f241ed71dc4",
"id": "CVE-2023-0841-ba244f6c",
"signature_version": "v1",
"digest": {
"function_hash": "188160872315200961537862609683092522980",
"length": 4905.0
}
}
]