CVE-2024-6064

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jun 17, 2024
Updated: Jun 20, 2024
CWE ID 416

Summary

CVE-2024-6064 is a recently disclosed vulnerability affecting GPAC 2.5-DEV-rev228-g11067ea92-master. The issue lies within the xmt_node_end function in the loader_xmt.c component of MP4Box. This vulnerability results in a use-after-free condition, which can be exploited by an attacker with local access. The exploit for this vulnerability has been made public, increasing the risk of potential attacks. To mitigate this issue, it is strongly advised to apply the patch with the identifier f4b3e4d2f91bc1749e7a924a8ab1171af03a355a8/c1b9c794bad8f262c56f3cf690567980d96662f5. The vulnerability has also been assigned the identifier VDB-268792 by the Vulnerability Database.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share