An issue in GPAC v.2.2.1 and before allows a local malicious user to cause a denial of service (DoS) via the ctts_box_read function of file src/isomedia/box_code_base.c.
gpac gpac