An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/gpac/gpac/issues/1335 | third party advisory exploit |
https://lists.debian.org/debian-lts-announce/2020/01/msg00017.html | third party advisory mailing list |