An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gfisomboxparseex() in isomedia/box_funcs.c.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-20162.json"