Monthly Archive: December 2019

CVE-2019-20169

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trak_Read() in isomedia/box_code_base.c. Date published : 2019-12-30 https://github.com/gpac/gpac/issues/1329

CVE-2019-20168

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gf_isom_box_dump_ex() in isomedia/box_funcs.c. Date published : 2019-12-30 https://github.com/gpac/gpac/issues/1333

CVE-2019-20167

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function senc_Parse() in isomedia/box_code_drm.c. Date published : 2019-12-30 https://github.com/gpac/gpac/issues/1330

CVE-2019-20166

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_dump() in isomedia/box_dump.c. Date published : 2019-12-30 https://github.com/gpac/gpac/issues/1331

CVE-2019-20164

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_box_del() in isomedia/box_funcs.c. Date published : 2019-12-30 https://github.com/gpac/gpac/issues/1332

CVE-2019-20160

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a stack-based buffer overflow in the function av1_parse_tile_group() in media_tools/av_parsers.c. Date published : 2019-12-30 https://github.com/gpac/gpac/issues/1334

CVE-2019-20149

ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by ‘constructor’: {‘name’:’Symbol’}. Hence, a crafted payload can overwrite this builtin attribute to...