Buffer overflow in the abstboxread function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
[
{
"signature_version": "v1",
"signature_type": "Function",
"id": "CVE-2021-31255-0a60e3ae",
"digest": {
"length": 2961.0,
"function_hash": "258107245646406056128312222982400552579"
},
"source": "https://github.com/gpac/gpac/commit/758135e91e623d7dfe7f6aaad7aeb3f791b7a4e5",
"target": {
"file": "src/isomedia/box_code_adobe.c",
"function": "abst_box_read"
},
"deprecated": false
},
{
"signature_version": "v1",
"signature_type": "Line",
"id": "CVE-2021-31255-52f9b7e4",
"digest": {
"line_hashes": [
"301382608729446269365151235785974737478",
"75054795995859823563815861102173490197",
"315456445040147107162021986690348805427",
"225363387238460481647379915371535623564",
"71383011012101062220920403852973743502",
"104677662135597084008771331119918235830",
"167561066845525403094025143433092494509",
"186300160836660328309793856079987044352",
"18497645211342342616849183313929535435",
"97517475652552002037337088837171814185",
"99531149942437825256231186111731274008",
"146128374334610018233541624921101709326",
"68743514124483372158713313988834004406",
"293300962827672730868945970121325663209",
"123394942549030022420997627546789938407",
"67237580303590551111106756338047361850",
"201571817422873628975451470563366099396",
"95167646658689461293592437673434324116",
"237344818774656427417038117711684189812",
"115123881686827374563751784127087421641",
"40654507533914248073688996812105205155",
"163486723301630551627883101424811552626",
"124249159815353891918539569287450864642",
"14390606280053364047803312310944680490",
"145159841787894039502457097424864257663",
"116598338347827938589087750683305816621",
"137214260005058337270646991498447434603",
"123394942549030022420997627546789938407",
"67237580303590551111106756338047361850",
"201571817422873628975451470563366099396",
"95167646658689461293592437673434324116",
"237344818774656427417038117711684189812",
"115123881686827374563751784127087421641",
"40654507533914248073688996812105205155",
"163486723301630551627883101424811552626",
"248237885344517459871987645121282351620",
"322956225853754395889529311189350061083",
"209025649325939162191136562801757898137",
"60609379034290175193739317541802162940",
"266324919719795563115772832387976086396",
"270142195143608987813010832335665371355",
"305515094175571391748610138480897457640",
"71383011012101062220920403852973743502",
"104677662135597084008771331119918235830",
"167561066845525403094025143433092494509",
"186300160836660328309793856079987044352",
"18497645211342342616849183313929535435",
"265869590104449316041780791064138757649",
"133283124060172814566465066055946039992",
"295199604222813044186767984753633152098",
"18893248543791392197083881052570092996",
"60609379034290175193739317541802162940",
"266324919719795563115772832387976086396",
"270142195143608987813010832335665371355",
"305515094175571391748610138480897457640",
"71383011012101062220920403852973743502",
"104677662135597084008771331119918235830",
"167561066845525403094025143433092494509",
"186300160836660328309793856079987044352",
"18497645211342342616849183313929535435",
"176718476252993577071858158525178524806",
"215269135801208712367927128104065341101"
],
"threshold": 0.9
},
"source": "https://github.com/gpac/gpac/commit/758135e91e623d7dfe7f6aaad7aeb3f791b7a4e5",
"target": {
"file": "src/isomedia/box_code_adobe.c"
},
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-31255.json"