The trakboxsize function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
{ "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Function", "target": { "file": "src/isomedia/box_code_base.c", "function": "trak_box_size" }, "deprecated": false, "digest": { "length": 770.0, "function_hash": "177716631601263422887816959889517703023" }, "id": "CVE-2021-32135-02afd05f", "source": "https://github.com/gpac/gpac/commit/b8f8b202d4fc23eb0ab4ce71ae96536ca6f5d3f8" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "src/isomedia/box_code_base.c" }, "deprecated": false, "digest": { "line_hashes": [ "180982079912359863713092613983514262329", "259171904111037091140515259864588543617", "104134878679528383612431513969623128882", "325562312999389756479242236541877472983" ], "threshold": 0.9 }, "id": "CVE-2021-32135-c6acd99d", "source": "https://github.com/gpac/gpac/commit/b8f8b202d4fc23eb0ab4ce71ae96536ca6f5d3f8" } ] }