Vulnerabilities
Vulnerable Software
Gpac:  >> Gpac  >> 0.7.1  Security Vulnerabilities
AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.
CVSS Score
6.5
EPSS Score
0.009
Published
2019-09-16
audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CVSS Score
6.5
EPSS Score
0.005
Published
2019-09-16
GPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-09-16
In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-07-16
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
CVSS Score
5.5
EPSS Score
0.003
Published
2019-05-30
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.
CVSS Score
7.5
EPSS Score
0.006
Published
2019-05-30
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
CVSS Score
7.8
EPSS Score
0.003
Published
2019-05-30
GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-04-15
gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.
CVSS Score
7.8
EPSS Score
0.004
Published
2019-04-15
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.
CVSS Score
7.8
EPSS Score
0.003
Published
2019-02-06


Contact Us

Shodan ® - All rights reserved