CVE detail
CVE-2020-11558 — CVE-2020-11558
Published 2020-04-05 · Modified 2026-06-17 · Vendor gpac · Product gpac · Source nvd
CRITICAL
severity
CVSS-derived band
0.0154
EPSS probability
exploitation probability, 30d
73.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References