The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avccomputepoc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
[
{
"signature_type": "Function",
"digest": {
"function_hash": "39295482979318475893292998550012608033",
"length": 10192.0
},
"target": {
"file": "src/media_tools/av_parsers.c",
"function": "gf_avc_read_sps_bs_internal"
},
"signature_version": "v1",
"id": "CVE-2021-40570-02f95021",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"162301846487824417085976151097850441387",
"290865607641083795548660822562839751511",
"36877859478553293821283680965112273961",
"277556399151842539648333058950472107336"
]
},
"target": {
"file": "src/media_tools/av_parsers.c"
},
"signature_version": "v1",
"id": "CVE-2021-40570-e7a12def",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302"
}
]