在 GPAC(版本直至提交 f1219cde)中发现了一个漏洞。受影响的元素是组件 MP4Box 中文件 scenegraph/vrml_tools.c 里的某个未知函数。对该函数的操作会导致空指针解引用问题。该攻击只能在本地环境中实施。利用该漏洞的信息已公开披露,并可能被用于攻击。将软件升级到版本 abi-16.23 即可解决此问题。补丁的标识为 49dee5cad329cfed310c1682703df7daa47df31a。建议升级受影响的组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GPAC | f1219cde |
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90613 | 3.3 LOW | GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion |
| CVE-2026-90612 | 3.3 LOW | GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion |
| CVE-2026-90611 | 3.3 LOW | GPAC MP4Box loader_xmt.c xmt_parse_element assertion |
| CVE-2026-90610 | 3.3 LOW | GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read |
No comments yet