An issue was discovered in gpac before 1.0.1. The abstboxread function in boxcodeadobe.c has a heap-based buffer over-read.
[
{
"signature_version": "v1",
"digest": {
"line_hashes": [
"277314140755109788143371680737817935350",
"232298900907090425745542428086106690466",
"3118555948760694791857422061136681976",
"201378029659621369504049888146417231228",
"9646116961418797508868064954538204670",
"69321621431637036410176467835980366341",
"179295534402896864219949575062942359518",
"6073203465298130345089151230691735587",
"281553742345317534852341050203622150490",
"35217966715946227375059836035260457811",
"106706448532342260716031826842529321344",
"127513953071112332676161738261724570753",
"218351240816685984196541729611924717816",
"180297467491725175461681799813821484237",
"3425233682095334149993458314078368289",
"131565954702825122889234981199252575761",
"77084698175041836346986895808166449474",
"35217966715946227375059836035260457811",
"106706448532342260716031826842529321344",
"127513953071112332676161738261724570753",
"178360246867399373236993985668530630846",
"104288676199915675063543297821355467916",
"177545270537430980269190602498644334325",
"194420556531594294546512662945502885704",
"201378029659621369504049888146417231228",
"79373116797220537460242813970099324782",
"104288676199915675063543297821355467916",
"177545270537430980269190602498644334325",
"194420556531594294546512662945502885704",
"201378029659621369504049888146417231228",
"52717418115184172042096511791401135732",
"162771469340685932696897447296929405192",
"220737230477673242185344055871594741219",
"297854710510699809118140348165141510714",
"161471613187234014298684317631809878358",
"193858737870657532089767597190897696650"
],
"threshold": 0.9
},
"signature_type": "Line",
"target": {
"file": "src/isomedia/box_code_adobe.c"
},
"deprecated": false,
"id": "CVE-2020-23931-20000af6",
"source": "https://github.com/gpac/gpac/commit/093283e727f396130651280609e687cd4778e0d1"
},
{
"signature_version": "v1",
"digest": {
"function_hash": "224388991912088206730772079559689292973",
"length": 2702.0
},
"signature_type": "Function",
"target": {
"file": "src/isomedia/box_code_adobe.c",
"function": "abst_box_read"
},
"deprecated": false,
"id": "CVE-2020-23931-59295b71",
"source": "https://github.com/gpac/gpac/commit/093283e727f396130651280609e687cd4778e0d1"
}
]