gpac
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*
- 2.4-rev0-g5d70253ac-HEAD
A segmentation fault vulnerability has been identified in gpac version 2.4 within the MP4Box application. The issue arises in the 'isom_cenc_get_sai_by_saiz_saio' function, located in 'src/isomedia/drm_sample.c'. This vulnerability is likely caused by dereferencing a null pointer, which can lead to a crash.
Exploitation of this vulnerability causes a segmentation fault, leading to a crash of the MP4Box application.
The vulnerability can be reproduced by cloning the gpac repository, checking out the specific commit '5d70253', and then compiling the application with AddressSanitizer enabled. After compiling, MP4Box can be run with the '-dash' option, which triggers the segmentation fault.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.