The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
[
{
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2021-31262-9465b1e5",
"digest": {
"length": 588.0,
"function_hash": "171931667066792198187769673904747214801"
},
"source": "https://github.com/gpac/gpac/commit/b2eab95e07cb5819375a50358d4806a8813b6e50",
"deprecated": false,
"target": {
"function": "gf_isom_av1_config_get",
"file": "src/isomedia/avc_ext.c"
}
},
{
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2021-31262-9abf0d0f",
"digest": {
"line_hashes": [
"247291634588424697610810039131654530737",
"176422099514206979543335388140707586494",
"269046133183686191219941028400761561449",
"134675652138491522443615927889994225586",
"18987815954972589176828380458224583412",
"37626700537071308498154276675350427352",
"65518661638453303631968316198865381232",
"133082178978553006112709492197247875131",
"101460720550159445199736183118792473044",
"37268567774305733487798192174292745485",
"70188106941334248530586398048017413348",
"130452226677282913404296419475473502135"
],
"threshold": 0.9
},
"source": "https://github.com/gpac/gpac/commit/b2eab95e07cb5819375a50358d4806a8813b6e50",
"deprecated": false,
"target": {
"file": "src/isomedia/avc_ext.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2021-31262-f1361b3e",
"digest": {
"length": 886.0,
"function_hash": "285958518593166966163525496266564232464"
},
"source": "https://github.com/gpac/gpac/commit/b2eab95e07cb5819375a50358d4806a8813b6e50",
"deprecated": false,
"target": {
"function": "AV1_RewriteESDescriptorEx",
"file": "src/isomedia/avc_ext.c"
}
}
]