In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filterparsedynargs function in filtercore/filter.c:1454, as demonstrated by GPAC. This can cause a denial of service (DOS).
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.0.0+dfsg1-2", "binary_name": "gpac" }, { "binary_version": "2.0.0+dfsg1-2", "binary_name": "gpac-dbgsym" }, { "binary_version": "2.0.0+dfsg1-2", "binary_name": "gpac-modules-base" }, { "binary_version": "2.0.0+dfsg1-2", "binary_name": "gpac-modules-base-dbgsym" }, { "binary_version": "2.0.0+dfsg1-2", "binary_name": "libgpac-dev" }, { "binary_version": "2.0.0+dfsg1-2", "binary_name": "libgpac11" }, { "binary_version": "2.0.0+dfsg1-2", "binary_name": "libgpac11-dbgsym" } ] }