CVE-2024-6062

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-6062
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6062.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6062
Downstream
Published
2024-06-17T20:15:15Z
Modified
2025-10-16T06:14:56.638939Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swfsvgaddisosample of the file src/filters/load_text.c of the component MP4Box. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as 31e499d310a48bd17c8b055a0bfe0fe35887a7cd. It is recommended to apply a patch to fix this issue. VDB-268790 is the identifier assigned to this vulnerability.

References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.5.2
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.8.0
v0.9.0
v0.9.0-preview

v1.*

v1.0.0
v1.0.1

v2.*

v2.0.0
v2.2.0
v2.4.0

Database specific

vanir_signatures

[
    {
        "source": "https://github.com/gpac/gpac/commit/31e499d310a48bd17c8b055a0bfe0fe35887a7cd",
        "target": {
            "function": "swf_svg_add_iso_sample",
            "file": "src/filters/load_text.c"
        },
        "id": "CVE-2024-6062-2a6e585e",
        "deprecated": false,
        "signature_version": "v1",
        "digest": {
            "function_hash": "33612371260713129794809450875098976894",
            "length": 680.0
        },
        "signature_type": "Function"
    },
    {
        "source": "https://github.com/gpac/gpac/commit/31e499d310a48bd17c8b055a0bfe0fe35887a7cd",
        "target": {
            "file": "src/filters/load_text.c"
        },
        "id": "CVE-2024-6062-75753734",
        "deprecated": false,
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "15743652608412309589575246353990975770",
                "230900430057019962807782420315460746588",
                "221948039272086289038339185297695541585",
                "220839803061096735700098006702996025588"
            ],
            "threshold": 0.9
        },
        "signature_type": "Line"
    }
]