CVE-2021-32138

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-32138
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32138.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-32138
Downstream
Published
2021-09-13T20:15:08Z
Modified
2025-10-21T05:48:20.981277Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.

References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.5.2
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.8.0
v0.9.0
v0.9.0-preview

v1.*

v1.0.0
v1.0.1

Database specific

vanir_signatures

[
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "72363230087630030596849941900056507927",
            "length": 38898.0
        },
        "target": {
            "file": "applications/mp4box/filedump.c",
            "function": "DumpTrackInfo"
        },
        "signature_version": "v1",
        "id": "CVE-2021-32138-94a412c0",
        "deprecated": false,
        "source": "https://github.com/gpac/gpac/commit/289ffce3e0d224d314f5f92a744d5fe35999f20b"
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "110813952207577778474837899797014853756",
                "270844214476017854922214101552119900190",
                "32932475279528246651705038658921617969",
                "18628512939991662238803177973967637439",
                "328807136156796949526559614132055125801",
                "236923671778649612870430103083481700222",
                "66169494858679149215744103948453711159",
                "155596384022551624924261727561163721496",
                "129210666194467045923794921218605162475",
                "180737934796336991252198006935756900992",
                "36846995504410589264330910748381873411",
                "134330799294180370222445525696240321460",
                "290997714870136359489958931391395770606",
                "36228315985012163088552575223570732090",
                "319297280601915710553291807514515423535",
                "60127297917787444437727825201856101588",
                "310868404963924679027873888371384724637",
                "215385272412777472972761329764328174975"
            ]
        },
        "target": {
            "file": "applications/mp4box/filedump.c"
        },
        "signature_version": "v1",
        "id": "CVE-2021-32138-eb9f6620",
        "deprecated": false,
        "source": "https://github.com/gpac/gpac/commit/289ffce3e0d224d314f5f92a744d5fe35999f20b"
    }
]