{"id":"CVE-2023-5998","details":"Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.","modified":"2026-04-12T09:09:26.047359Z","published":"2023-11-07T19:15:12.737Z","references":[{"type":"FIX","url":"https://github.com/gpac/gpac/commit/db74835944548fc3bdf03121b0e012373bdebb3e"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/ea02a231-b688-422b-a881-ef415bcf6113"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"0"},{"fixed":"db74835944548fc3bdf03121b0e012373bdebb3e"}]},{"type":"GIT","repo":"https://github.com/gpac/gpac","events":[{"introduced":"0"},{"fixed":"db74835944548fc3bdf03121b0e012373bdebb3e"}]}],"versions":["v0.5.2","v0.6.0","v0.9.0","v0.9.0-preview","v1.0.0","v2.0.0","v2.2.0"],"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"2.3.0"}]}],"vanir_signatures":[{"source":"https://github.com/gpac/gpac/commit/db74835944548fc3bdf03121b0e012373bdebb3e","id":"CVE-2023-5998-19a525f5","target":{"file":"src/filters/reframe_mpgvid.c"},"digest":{"line_hashes":["210191145274763799405933178010455164029","280948375926152932462146658933811441473","238976147467989108832449711727758471517","269232271506285179557076417147039547833"],"threshold":0.9},"signature_type":"Line","signature_version":"v1","deprecated":false},{"source":"https://github.com/gpac/gpac/commit/db74835944548fc3bdf03121b0e012373bdebb3e","id":"CVE-2023-5998-2f799638","target":{"file":"src/filters/reframe_mpgvid.c","function":"mpgviddmx_process"},"digest":{"length":13477,"function_hash":"180636824058638418826611626467131550999"},"signature_type":"Function","signature_version":"v1","deprecated":false}],"vanir_signatures_modified":"2026-04-12T09:09:26Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5998.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}