In filters/reframelatm.c in GPAC 1.0.1 there is a Null Pointer Dereference, when gffilterpckget_data is called. The first arg pck may be null with a crafted mp4 file,which results in a crash.
{ "vanir_signatures": [ { "digest": { "function_hash": "322881962646193761510325288580375918980", "length": 3034.0 }, "id": "CVE-2021-30199-5b485d5f", "source": "https://github.com/gpac/gpac/commit/b2db2f99b4c30f96e17b9a14537c776da6cb5dca", "signature_version": "v1", "signature_type": "Function", "target": { "file": "src/filters/reframe_latm.c", "function": "latm_dmx_process" }, "deprecated": false }, { "digest": { "threshold": 0.9, "line_hashes": [ "67582710314780463758571953239788679651", "290015795950904442635474948029970013247", "273375960481668448140498039584626171914", "327052348851824933168734381584993964613", "177691872155673446041301130712305766036", "88248128088414560189744820890003820416", "162038618548578233682791090979352532957", "179112026165925033742743549772726948823", "237535298546394459331137734534040221136", "219513559262009853049938752600817905056", "193299817810724375760158972926776532632" ] }, "id": "CVE-2021-30199-f14e6216", "source": "https://github.com/gpac/gpac/commit/b2db2f99b4c30f96e17b9a14537c776da6cb5dca", "signature_version": "v1", "signature_type": "Line", "target": { "file": "src/filters/reframe_latm.c" }, "deprecated": false } ] }