Memory leak in the gfisomoinfreadentry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
[
{
"id": "CVE-2021-33366-055ee822",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"300921247869268374670114649845646114000",
"268115012844309457581256500449888999880",
"112605582290686948143665129381495412118",
"167233635158787946113545385271266292907",
"339594173779950548247693231596897312929"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/0a85029d694f992f3631e2f249e4999daee15cbf",
"target": {
"file": "src/isomedia/avc_ext.c"
}
},
{
"id": "CVE-2021-33366-68dbf00a",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 2999.0,
"function_hash": "221996246729804369847592071767377089397"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/0a85029d694f992f3631e2f249e4999daee15cbf",
"target": {
"function": "gf_isom_oinf_read_entry",
"file": "src/isomedia/avc_ext.c"
}
}
]