CyberRota Analysis
AI-GeneratedThe vulnerability affects the GPAC MP4Box component, specifically in the gf_node_get_name function, leading to a use-after-free condition that can be exploited remotely. This could allow an attacker to execute arbitrary code or cause a denial of service. Organizations using GPAC should prioritize upgrading to version abi-16.23 to mitigate the risk associated with this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 is recommended to address this issue. The name of the patch is 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.