CVE-2023-1448

Publication date 17 March 2023

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

A vulnerability, which was classified as problematic, was found in GPAC 2.3-DEV-rev35-gbbca86917-master. This affects the function gf_m2ts_process_sdt of the file media_tools/mpegts.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223293 was assigned to this vulnerability.

Read the notes from the security team

Status

Package Ubuntu Release Status
gpac 25.04 plucky Not in release
24.10 oracular Not in release
24.04 LTS noble
Needs evaluation
23.10 mantic Not in release
23.04 lunar Ignored end of life, was needs-triage
22.10 kinetic Ignored end of life, was needs-triage
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Notes


sbeattie

PoC in github issue as of 2023-03-20, fix committed upstream, but no release made.

Severity score breakdown

Parameter Value
Base score 5.3 · Medium
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L