An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the cttsboxread function of file src/isomedia/boxcodebase.c.