An issue was discovered in boxcodeapple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilstitemRead.
[
{
"id": "CVE-2020-19488-15bb639f",
"source": "https://github.com/gpac/gpac/commit/6170024568f4dda310e98ef7508477b425c58d09",
"target": {
"function": "ilst_item_box_read",
"file": "src/isomedia/box_code_apple.c"
},
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "76557726008365586309866346198720532336",
"length": 1729.0
},
"signature_type": "Function"
},
{
"id": "CVE-2020-19488-af8e27b5",
"source": "https://github.com/gpac/gpac/commit/6170024568f4dda310e98ef7508477b425c58d09",
"target": {
"file": "src/isomedia/box_code_apple.c"
},
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"93052003416229134326844688799505428902",
"137638215521662659213169629412788171523",
"218856652493421116641591856317043504045",
"215335284481261113098767767928878411580",
"300668904883607872971667183085576413148",
"130934968920720747450702108576285489587",
"313525340958840565967647329992440436085",
"324483646226687389449473943369863747743"
],
"threshold": 0.9
},
"signature_type": "Line"
}
]