An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audiosampleentryRead in isomedia/boxcodebase.c does not properly decide when to make gfisomboxdel calls. This leads to various use-after-free outcomes involving mdiaRead, gfisomdeletemovie, and gfisomparsemovieboxes.
An issue was discovered in gpac 0.8.0. The gfodfdelipmptool function in odfcode.c has a heap-based buffer over-read.
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gfhintertrackfinalize() in mediatools/isomhinter.c.
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isomstore.c.
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gprtpbuilderdoavc() in ietf/rtppckmpeg4.c.
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gfisomboxdel() in isomedia/boxfuncs.c.
An issue was discovered in gpac 0.8.0. The strdup function in boxcodebase.c has a heap-based buffer over-read.
An issue was discovered in gpac 0.8.0. The gfhintertrackprocess function in isomhintertrackprocess.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file
An issue was discovered in gpac 0.8.0. The GetGhostNum function in stblread.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
An issue was discovered in gpac 0.8.0. The gfmedianaluremoveemulationbytes function in avparsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
An issue was discovered in gpac 0.8.0. The dumpdatahex function in boxdump.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
Memory leak in the sgpdparseentry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
Memory leak in the sencParse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isomintern.c, which allows attackers to cause a denial of service (DoS) via a crafted input.
An issue was discovered in gpac 0.8.0. The stblGetSampleSize function in isomedia/stblread.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.
An issue was discovered in gpac 0.8.0. The ODReadUTF8String function in odfcode.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted media file.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gfisomboxdumpex() in isomedia/boxfuncs.c.
An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metxNew in isomedia/boxcodebase.c and abstRead in isomedia/boxcodeadobe.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trakRead() in isomedia/boxcodebase.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GFIPMPXAUTHDelete() in odf/ipmpxcode.c.
dimCRead in isomedia/boxcode3gpp.c in GPAC 0.8.0 has a stack-based buffer overflow.
A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gfisomgettrackid function, which causes a denial of service.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a memory leak in dinfNew() in isomedia/boxcodebase.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gfisomdump() in isomedia/boxdump.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gfisomboxparseex() in isomedia/boxfuncs.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gfodfavccfgwritebs() in odf/descriptors.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function sencParse() in isomedia/boxcodedrm.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gfisomboxdel() in isomedia/boxfuncs.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGFIPMPXWatermarkingInit() in odf/ipmpxcode.c.
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilstitemRead() in isomedia/boxcodeapple.c.