CyberRota Analysis
AI-GeneratedA use-after-free vulnerability exists in the gf_sg_script_load function of the MP4Box component in GPAC, which can be exploited remotely. This flaw may lead to potential arbitrary code execution, making it critical for users of GPAC versions up to f1219cde to prioritize upgrading to version abi-16.23 to mitigate the risk. Organizations utilizing GPAC in their applications should take immediate action to apply the patch to safeguard their systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a manipulation results in use after free. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version abi-16.23 is sufficient to fix this issue. The patch is named 9eb40df4448b88d6a6ce3454657c06f47eff0b24. It is advisable to upgrade the affected component.