A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gfisomgettrackid function, which causes a denial of service.
[
{
"signature_version": "v1",
"signature_type": "Line",
"id": "CVE-2020-25427-03a92b01",
"digest": {
"line_hashes": [
"276733721440616873231165682537985480708",
"241816059773233637622238702292792174145",
"144004370354497051973423319034534800561",
"81144324175758793573471338518868339901",
"331597519283809026471401842101136177810",
"253014626197910862799703804428793466586",
"132310487882069734521023974123723390417",
"184979487053596769801266436670628342130",
"210690139372428086931097566046588596402",
"334445620841357926183800452934868122649",
"102084570291325465471729105453860979236",
"291752034486566769225382232384075790004",
"188659798654361141089446755525976142299"
],
"threshold": 0.9
},
"source": "https://github.com/gpac/gpac/commit/8e585e623b1d666b4ef736ed609264639cb27701",
"target": {
"file": "src/isomedia/box_funcs.c"
},
"deprecated": false
},
{
"signature_version": "v1",
"signature_type": "Function",
"id": "CVE-2020-25427-4a4d5cbc",
"digest": {
"length": 4385.0,
"function_hash": "164916447853270442724752484460171499615"
},
"source": "https://github.com/gpac/gpac/commit/8e585e623b1d666b4ef736ed609264639cb27701",
"target": {
"file": "src/isomedia/box_funcs.c",
"function": "gf_isom_box_parse_ex"
},
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25427.json"