CVE-2020-23928: Gpac

High severity, CVSS 7.1. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.

Affected products

  • Gpac Gpac: before 1.0.1 (fixed in 1.0.1)

Published 2021-04-21. Last modified 2026-06-17.