CVE-2024-6062

Source
https://cve.org/CVERecord?id=CVE-2024-6062
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6062.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6062
Downstream
Published
2024-06-17T19:31:10Z
Modified
2026-08-12T15:16:10Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
GPAC MP4Box load_text.c swf_svg_add_iso_sample null pointer dereference
Details

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 31e499d310a48bd17c8b055a0bfe0fe35887a7cd. It is recommended to apply a patch to fix this issue. VDB-268790 is the identifier assigned to this vulnerability.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6062.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.5-DEV-rev228-g11067ea92-master"
                },
                {
                    "last_affected": "2.5-DEV-rev228-g11067ea92-master"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0
v2.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6062.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "33612371260713129794809450875098976894",
            "length": 680
        },
        "id": "CVE-2024-6062-2a6e585e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/31e499d310a48bd17c8b055a0bfe0fe35887a7cd",
        "target": {
            "file": "src/filters/load_text.c",
            "function": "swf_svg_add_iso_sample"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "15743652608412309589575246353990975770",
                "230900430057019962807782420315460746588",
                "221948039272086289038339185297695541585",
                "220839803061096735700098006702996025588"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2024-6062-75753734",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/31e499d310a48bd17c8b055a0bfe0fe35887a7cd",
        "target": {
            "file": "src/filters/load_text.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:16:10Z"