Impact
The vulnerability is a heap-based buffer overflow in the gf_url_concatenate_ex function of GPAC's URL handler (utils/url.c). An attacker could provide crafted inputs to overflow a buffering memory and causing crashes or malicious code execution. The weakness falls under CWE-119 (Improper Input Validation-based Buffer Overflow).
Affected Systems
121 The fix is available in release abi-16.23, which incorporates the patch with commit afca1f1181668d85941d51ed1adf647807d5d975. Only the GPAC product from vendor GPAC is impacted.
Risk and Exploitability
The CVSS score is 2.4, indicating low severity, and the EPSS score is less than 1%, reflecting a very low probability of exploitation. The vulnerability requires local execution, and it is not listed in the CISA KEV catalog. Because local access is required, the threat to an organization is limited to environments where users can run GPAC or where GPAC is exposed to untrusted data on a local machine.
OpenCVE Enrichment