OSV-2024-719

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gpac/OSV-2024-719.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-719
Published
2024-08-07T00:05:22.699506Z
Modified
2026-02-07T14:19:32.035799Z
Summary
Heap-buffer-overflow in hevc_ref_pic_lists_modification
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=70890

Crash type: Heap-buffer-overflow WRITE 4
Crash state:
hevc_ref_pic_lists_modification
gf_hevc_parse_nalu_bs
gf_inspect_dump_nalu_internal
References

Affected packages

OSS-Fuzz / gpac

Package

Name
gpac
Purl
pkg:generic/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.2
abi-16.3
abi-16.4
abi-16.5
testtag0.*
testtag0.1
v26.*
v26.02.0

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

introduced_range
"cf9017e7f44c1d0c9a4e520083aece0d3ab329f7:df8121066cf8fb25cc70adf7ca8b35bda82fe216"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gpac/OSV-2024-719.yaml"