An issue was discovered in MP4Box in GPAC 0.7.1. The function urnRead in isomedia/boxcodebase.c has a heap-based buffer over-read.
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/boxdump.c function hdlrdump.
Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.
GPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmxparsetags function.
GPAC v2.3 was detected to contain a buffer overflow via the function gfisomnewgenericsampledescription function in the isomedia/isomwrite.c:4577
NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.
A security vulnerability has been detected in GPAC up to 2.4.0. This affects the function gftextimportsrtbifs of the file src/scenemanager/texttobifs.c of the component SRT Subtitle Import. Such manipulation leads to out-of-bounds write. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The name of the patch is 10c73b82cf0e367383d091db38566a0e4fe71772. It is best practice to apply a patch to resolve this issue.
GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs during NHML file parsing in src/filters/dmxnhml.c. The value of the xmlHeaderEnd XML attribute is copied from att->value into szXmlHeaderEnd[1000] using strcpy() without any length validation. If the input exceeds 1000 bytes, it overwrites beyond the stack buffer boundary. Commit 9bd7137fded2db40de61a2cf3045812c8741ec52 patches the issue.
GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability was discovered in GPAC MP4Box. The vulnerability exists in the gfxmlparsebitsequencebs function in utils/xmlbincustom.c when processing a crafted NHML file containing malicious <BS> (BitSequence) elements. An attacker can exploit this by providing a specially crafted NHML file, causing an out-of-bounds write on the heap. This issue has been via commit 86b0e36.
A use-after-free in the gfseiloadfromstateinternal function (/filters/seiload.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 TS file.
Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function
GPAC through 0.7.1 has a Buffer Overflow in the gfmediaavcreadsps function in mediatools/avparsers.c, a different vulnerability than CVE-2018-1000100.
In GPAC 0.7.1 and earlier, gftextgetutf8line in mediatools/textimport.c in libgpacstatic.a allows an out-of-bounds write because a certain -1 return value is mishandled.
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gfisomboxdumpstartex at /isomedia/boxfuncs.c.
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at isomedia/isomintern.c.
gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasherconfigurepid function at /src/filters/dasher.c.
gpac v2.2.1 was discovered to contain a memory leak via the dstprops variable in the gffilterpidmergepropertiesinternal function.
gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfioblob variable in the gffileiofromblob function.
An out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .gsf file.
A buffer overflow in the vobsubgetsubpicduration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
A stack overflow in the dumpttxtsample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
A NULL pointer dereference in the gfodfvvccfgwritebs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
A stack buffer overflow in the fileinprocess function (infile.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
A segmentation violaton in the gfhevcreadspsbsinternal function (mediatools/avparsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.
A use-after-free in the gffilterpidinstswapdeletetask function (/filtercore/filterpid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.
A buffer overflow in the gfmediaimport function (/mediatools/avparsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Unchecked Return Value in GitHub repository gpac/gpac prior to 2.2.2.
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.
A heap overflow in the aviparseinputfile() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file.
A NULL pointer dereference in the cttsboxwrite function (isomedia/boxcodebase.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.