CyberRota Analysis
AI-GeneratedThe GPAC MP4Box component is vulnerable to a use-after-free condition in the gf_node_changed_internal function, which can be exploited remotely. This flaw could lead to potential denial-of-service attacks or arbitrary code execution. Organizations using affected versions should prioritize upgrading to version abi-16.23 to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is able to resolve this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.