A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtraboxwrite function in /boxcodebase.c, which causes a Denial of Service. This vulnerability was fixed in commit 71f9871.
{ "vanir_signatures": [ { "signature_version": "v1", "target": { "function": "gf_cfg_init", "file": "src/utils/os_config_init.c" }, "signature_type": "Function", "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "deprecated": false, "digest": { "length": 2924.0, "function_hash": "331609225902553284938660782849123559724" }, "id": "CVE-2022-24249-00ec9c94" }, { "signature_version": "v1", "target": { "file": "src/utils/os_config_init.c" }, "signature_type": "Line", "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "deprecated": false, "digest": { "line_hashes": [ "253854454906731252594870579307233588965", "179864446493625039430457959093405636565", "157047988769606476955262936216865999399", "25205688373900634743508465492002274847" ], "threshold": 0.9 }, "id": "CVE-2022-24249-84a001c2" }, { "signature_version": "v1", "target": { "function": "PrintUsage", "file": "applications/mp4client/main.c" }, "signature_type": "Function", "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "deprecated": false, "digest": { "length": 1136.0, "function_hash": "116287927203832314234354772323596679187" }, "id": "CVE-2022-24249-abddd526" }, { "signature_version": "v1", "target": { "file": "applications/mp4client/main.c" }, "signature_type": "Line", "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "deprecated": false, "digest": { "line_hashes": [ "110287411499135302499254568127786275886", "196881605958314966606044579045527764763", "211928352066196418331258856473204866912", "280195963159516847825224043850516008460" ], "threshold": 0.9 }, "id": "CVE-2022-24249-dde39a3b" } ] }