Buffer overflow in the tencboxread function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file, related invalid IV sizes.
[
{
"signature_type": "Function",
"source": "https://github.com/gpac/gpac/commit/8986422c21fbd9a7bf6561cae65aae42077447e8",
"digest": {
"function_hash": "4849708879882613840022375048679469026",
"length": 773.0
},
"target": {
"file": "src/isomedia/box_code_drm.c",
"function": "tenc_box_read"
},
"id": "CVE-2021-31254-dfdec9a9",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"source": "https://github.com/gpac/gpac/commit/8986422c21fbd9a7bf6561cae65aae42077447e8",
"digest": {
"threshold": 0.9,
"line_hashes": [
"9954390780939663405509649729900886593",
"329965104858358940077373459695648792305",
"325748983408990306817580626227468735250",
"68100611574058582112789217219950522545",
"218938213027427872819405339186102037022",
"296214368139074869037793616046949433081"
]
},
"target": {
"file": "src/isomedia/box_code_drm.c"
},
"id": "CVE-2021-31254-f4b9a9b3",
"deprecated": false,
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-31254.json"