The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gfisomgetpaytcount function in hint_track.c, which allows attackers to cause a denial of service.
[
{
"id": "CVE-2021-40576-642b86cc",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 460.0,
"function_hash": "64669718982500005998952664897227464772"
},
"target": {
"function": "GetHintFormat",
"file": "src/isomedia/hint_track.c"
},
"source": "https://github.com/gpac/gpac/commit/ad18ece95fa064efc0995c4ab2c985f77fb166ec",
"signature_type": "Function"
},
{
"id": "CVE-2021-40576-e15d50ed",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"213132367431935810995875342538304866537",
"69422952422666335137015309587630551427",
"154475117685622613766551368937792949715",
"247987700451396011635532392404281105653"
],
"threshold": 0.9
},
"target": {
"file": "src/isomedia/hint_track.c"
},
"source": "https://github.com/gpac/gpac/commit/ad18ece95fa064efc0995c4ab2c985f77fb166ec",
"signature_type": "Line"
}
]