Impact
A vulnerability exists in the HevcVpsUnit::setFPS function of justdan96 tsMuxer up to version 2.7.0. By manipulating the track_id argument, a local attacker can trigger a denial of service. The flaw is identified as CWE‑404, and it causes the tsMuxer process to terminate, disrupting media multiplexing tasks.
Affected Systems
The affected product is justdan96 tsMuxer, with all releases up to and including 2.7.0 included. These older releases are no longer supported by the maintainer, so users running them are at risk. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The EPSS score is not available, so a quantitative exploitation probability cannot be determined. The vulnerability is not listed in the CISA KEV catalog. Local access is required to exploit the flaw, which limits the threat to users who can run code on the affected machine. Because a publicly available proof‑of‑concept exists, any local user who can interact with tsMuxer could trigger the denial of service, potentially interrupting streaming services or other dependent processes.
OpenCVE Enrichment