The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avccomputepoc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
[
{
"source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "gf_avc_read_sps_bs_internal",
"file": "src/media_tools/av_parsers.c"
},
"id": "CVE-2021-40570-02f95021",
"signature_type": "Function",
"digest": {
"length": 10192.0,
"function_hash": "39295482979318475893292998550012608033"
}
},
{
"source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "src/media_tools/av_parsers.c"
},
"id": "CVE-2021-40570-e7a12def",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"162301846487824417085976151097850441387",
"290865607641083795548660822562839751511",
"36877859478553293821283680965112273961",
"277556399151842539648333058950472107336"
]
}
}
]