在 GPAC(截至提交 f1219cde)中发现了漏洞。该漏洞影响了组件 MP4Box 中文件 scenegraph/svg_attributes.c 里的函数 gf_svg_attributes_copy。执行特定操作会导致缓冲区越界读取(buffer over-read)。该漏洞仅可通过本地访问触发。该漏洞的利用方式已公开,存在被利用的风险。升级至版本 abi-16.23 可缓解此问题。修复补丁的标识为 afca1f1181668d85941d51ed1adf647807d5d975。建议升级受影响的组件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GPAC | f1219cde |
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90613 | 3.3 LOW | GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion |
| CVE-2026-90612 | 3.3 LOW | GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion |
| CVE-2026-90611 | 3.3 LOW | GPAC MP4Box loader_xmt.c xmt_parse_element assertion |
| CVE-2026-90609 | 3.3 LOW | GPAC MP4Box vrml_tools.c null pointer dereference |
No comments yet