Description
Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
References
https://github.com/gpac/gpac/commit/fe5155cf047252d1c4cb91602048bfa682af0ea7
PatchThird Party Advisory
https://github.com/gpac/gpac/issues/1783
ExploitIssue TrackingPatchThird Party Advisory
https://github.com/gpac/gpac/commit/fe5155cf047252d1c4cb91602048bfa682af0ea7
PatchThird Party Advisory
https://github.com/gpac/gpac/issues/1783
ExploitIssue TrackingPatchThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
5.5 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-09-13T19:15:13.987Z
5 years agoLast modified
2026-06-17T03:54:30.783Z
3 months ago