The DumpTrackInfo function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
[
{
"signature_type": "Function",
"digest": {
"function_hash": "72363230087630030596849941900056507927",
"length": 38898.0
},
"target": {
"file": "applications/mp4box/filedump.c",
"function": "DumpTrackInfo"
},
"signature_version": "v1",
"id": "CVE-2021-32138-94a412c0",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/289ffce3e0d224d314f5f92a744d5fe35999f20b"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"110813952207577778474837899797014853756",
"270844214476017854922214101552119900190",
"32932475279528246651705038658921617969",
"18628512939991662238803177973967637439",
"328807136156796949526559614132055125801",
"236923671778649612870430103083481700222",
"66169494858679149215744103948453711159",
"155596384022551624924261727561163721496",
"129210666194467045923794921218605162475",
"180737934796336991252198006935756900992",
"36846995504410589264330910748381873411",
"134330799294180370222445525696240321460",
"290997714870136359489958931391395770606",
"36228315985012163088552575223570732090",
"319297280601915710553291807514515423535",
"60127297917787444437727825201856101588",
"310868404963924679027873888371384724637",
"215385272412777472972761329764328174975"
]
},
"target": {
"file": "applications/mp4box/filedump.c"
},
"signature_version": "v1",
"id": "CVE-2021-32138-eb9f6620",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/289ffce3e0d224d314f5f92a744d5fe35999f20b"
}
]