gpac.gpac is vulnerable to Out-of-bounds Read
47
Medium Risk
GPAC's MP4Box imports DIMS samples from NHML files in nhmldmx_send_sample within filters/dmx_nhml.c. When a sample specifies a negative dataLength, the allocated sample buffer is left without a terminating null byte and a subsequent strstr scan runs far past the end of the buffer. A crafted NHML file thus causes a large heap out-of-bounds read that can crash the tool or disclose adjacent heap memory. The fix bounds the sample length and terminates the buffer before scanning.
You are affected if you are using a version that falls within the vulnerable range and you import an untrusted NHML file that carries DIMS samples.
gpac.gpac is vulnerable to Out-of-bounds Read in versions 1.0.0 - 26.02.0.
Upgrade the gpac.gpac and/or the gpac library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.