An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldumpsendheader located in write_nhml.c. It allows an attacker to cause Denial of Service.
[
{
"id": "CVE-2020-23930-11407349",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "src/filters/write_nhml.c"
},
"digest": {
"line_hashes": [
"273365987222454724297359249226530248524",
"148396435000441226309173423878912363442",
"45585237414436127171925576937545840635",
"278661613006658029934394344360736263072"
],
"threshold": 0.9
},
"source": "https://github.com/gpac/gpac/commit/9eeac00b38348c664dfeae2525bba0cf1bc32349"
},
{
"id": "CVE-2020-23930-372daa3a",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "src/filters/write_nhml.c",
"function": "nhmldump_send_header"
},
"digest": {
"function_hash": "308095444081921113363681641521013641954",
"length": 5664.0
},
"source": "https://github.com/gpac/gpac/commit/9eeac00b38348c664dfeae2525bba0cf1bc32349"
},
{
"id": "CVE-2020-23930-757087f4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "applications/mp4box/main.c",
"function": "mp4boxMain"
},
"digest": {
"function_hash": "217265730055898313492699544444049551658",
"length": 59602.0
},
"source": "https://github.com/gpac/gpac/commit/9eeac00b38348c664dfeae2525bba0cf1bc32349"
},
{
"id": "CVE-2020-23930-f5d9e11c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "applications/mp4box/main.c"
},
"digest": {
"line_hashes": [
"324751016173844255721258964487809744136",
"291360413679397562029818288540798853298",
"135282687474570625443943415782746560765",
"89071588151960392334557332777645754063"
],
"threshold": 0.9
},
"source": "https://github.com/gpac/gpac/commit/9eeac00b38348c664dfeae2525bba0cf1bc32349"
}
]