The HintFile function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
[
{
"digest": {
"function_hash": "53835788517663611656893566215389549396",
"length": 3821.0
},
"target": {
"file": "applications/mp4box/main.c",
"function": "HintFile"
},
"signature_version": "v1",
"id": "CVE-2021-31257-23554903",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/87afe070cd6866df7fe80f11b26ef75161de85e0",
"signature_type": "Function"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"115810165752277888506123696991728882828",
"266874972863759520941413163698542361826",
"209509910709474573358654816600514102176",
"124401416960144259094587606488848084048"
]
},
"target": {
"file": "applications/mp4box/main.c"
},
"signature_version": "v1",
"id": "CVE-2021-31257-8e628971",
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/87afe070cd6866df7fe80f11b26ef75161de85e0",
"signature_type": "Line"
}
]