An issue was discovered in gpac before 1.0.1. The abstboxread function in boxcodeadobe.c has a heap-based buffer over-read.
{
"cpe": "cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.0.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-08T23:35:09Z"
[
{
"target": {
"function": "abst_box_read",
"file": "src/isomedia/box_code_adobe.c"
},
"id": "CVE-2020-23928-040aaef5",
"digest": {
"function_hash": "224329052296549846793002160328219614017",
"length": 2965.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/gpac/gpac/commit/8e05648d6b4459facbc783025c5c42d301fef5c3"
},
{
"target": {
"file": "src/isomedia/box_code_adobe.c"
},
"id": "CVE-2020-23928-3e8f7045",
"digest": {
"line_hashes": [
"314450098367280310849354577419420946517",
"64683914037193031225924045831124023185",
"191435674754192633117331026067058159153",
"320789349979153142793911569853053630401"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/gpac/gpac/commit/8e05648d6b4459facbc783025c5c42d301fef5c3"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-23928.json"