In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as demonstrated by GPAC. This can cause a denial of service (DOS).
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/gpac/gpac/issues/1906 | issue tracking patch exploit third party advisory |
https://www.debian.org/security/2023/dsa-5411 | vendor advisory |