gfbin128parse in utils/osdivers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafteddrm_file.xml file.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"288643665370547427216201665600783405623",
"273161725965139220804160143887329130351",
"41323113871138413023466185707709095841",
"271242982961420141875599280728740783827",
"58069941314692178306384077041618027520",
"303406837877777390534022729306922853973"
]
},
"target": {
"file": "src/utils/os_divers.c"
},
"signature_type": "Line",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/f3698bb1bce62402805c3fda96551a23101a32f9",
"signature_version": "v1",
"id": "CVE-2019-11222-329de307"
},
{
"digest": {
"function_hash": "17516007253867619324918447013573434798",
"length": 666.0
},
"target": {
"function": "gf_bin128_parse",
"file": "src/utils/os_divers.c"
},
"signature_type": "Function",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/f3698bb1bce62402805c3fda96551a23101a32f9",
"signature_version": "v1",
"id": "CVE-2019-11222-a780c5a2"
}
]