CVE-2023-1450

NameCVE-2023-1450
DescriptionA vulnerability was found in MP4v2 2.1.2 and classified as problematic. This issue affects the function DumpTrack of the file mp4trackdump.cpp. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223295.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mp4v2 (PTS)jessie2.0.0~dfsg0-3vulnerable
stretch2.0.0~dfsg0-5vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mp4v2sourcejessie(unfixed)end-of-life
mp4v2sourcestretch(unfixed)end-of-life
mp4v2source(unstable)(unfixed)

Search for package or bug name: Reporting problems