In GPAC prior to 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/mpegts.c.
Debian Bug report logs -
#994746
ccextractor embeds unpatched and vulnerable source code from gpac
Package:
ccextractor;
Maintainer for ccextractor is Freexian Packaging Team <team+freexian@trackerdebianorg>; Source for ccextractor is src:ccextractor (PTS, buildd, popcon)
Reported by: Neil Williams <codehelp@debianorg& ...