There is a Null Pointer Dereference in function filtercore/filterpck.c:gffilterpcknewallocinternal in GPAC 1.0.1. The pid comes from function av1dmxparseflushsample, the ctx.opid maybe NULL. The result is a crash in gffilterpcknewalloc_internal.
[
{
"target": {
"function": "av1dmx_parse_flush_sample",
"file": "src/filters/reframe_av1.c"
},
"signature_version": "v1",
"digest": {
"length": 938.0,
"function_hash": "58711868154071436767150960965126598198"
},
"source": "https://github.com/gpac/gpac/commit/13dad7d5ef74ca2e6fe4010f5b03eb12e9bbe0ec",
"deprecated": false,
"id": "CVE-2021-30015-8c801ea3",
"signature_type": "Function"
},
{
"target": {
"file": "src/filters/reframe_av1.c"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"165766728170830317054956550839990078013",
"267444251905127156116583452213721798107",
"303411012733722853373672359583694420871"
],
"threshold": 0.9
},
"source": "https://github.com/gpac/gpac/commit/13dad7d5ef74ca2e6fe4010f5b03eb12e9bbe0ec",
"deprecated": false,
"id": "CVE-2021-30015-aaf0fc37",
"signature_type": "Line"
}
]