Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or execute arbitrary code via a crafted file.
[
{
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/328def7d3b93847d64ecb6e9e0399684e57c3eca",
"target": {
"function": "Media_CheckDataEntry",
"file": "src/isomedia/media.c"
},
"digest": {
"length": 826.0,
"function_hash": "284792179839374304082149816269135201397"
},
"id": "CVE-2021-32137-2e1c2167"
},
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/gpac/gpac/commit/328def7d3b93847d64ecb6e9e0399684e57c3eca",
"target": {
"file": "src/isomedia/media.c"
},
"digest": {
"line_hashes": [
"291249380859904332633641164920843666578",
"226897459076574812555870498271110113061",
"335433438652266364451620202234763074335",
"230842406680219397682270184490128442553",
"224490458383372915941042163679871284762",
"208175748052662061258604624397459148150",
"340234610476939007714845125844834320246"
],
"threshold": 0.9
},
"id": "CVE-2021-32137-5b35e7ee"
}
]