An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGFIPMPXRemoveToolNotificationListener in odf/ipmpxcode.c in libgpac.a, as demonstrated by MP4Box.
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gfisomgetoriginalformattype at isomedia/drmsample.c in libgpac.a, as demonstrated by MP4Box.
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
AVCDuplicateConfig() at isomedia/avcext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfgnew->AVCLevelIndication = cfg->AVCLevelIndication;" but cfg could be NULL.
audiosampleentryAddBox() at isomedia/boxcodebase.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
GPAC 0.7.1 has a memory leak in dinfRead in isomedia/boxcodebase.c.
GPAC 0.7.1 has a buffer overflow issue in gfimportmessage() in mediaimport.c.
gfbin128parse in utils/osdivers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafteddrmfile.xml file.