#VU35488 Out-of-bounds read in GPAC - CVE-2018-21016
Published: September 16, 2019 / Updated: December 20, 2022
GPAC
GPAC
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1. A remote attacker can perform a denial of service (heap-based buffer over-read and application crash) via a crafted file.