The gfmediaexport_filters function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
{ "vanir_signatures": [ { "target": { "file": "src/media_tools/media_export.c", "function": "gf_media_export_filters" }, "id": "CVE-2021-32438-2cf87496", "source": "https://github.com/gpac/gpac/commit/00194f5fe462123f70b0bae7987317b52898b868", "digest": { "length": 10399.0, "function_hash": "110411369548654099994106716865860766881" }, "signature_version": "v1", "signature_type": "Function", "deprecated": false }, { "target": { "file": "src/media_tools/media_export.c" }, "id": "CVE-2021-32438-704c91a5", "source": "https://github.com/gpac/gpac/commit/00194f5fe462123f70b0bae7987317b52898b868", "digest": { "line_hashes": [ "276834135827962349594238480044194601543", "104037118183956055809821158770854310676", "142501862856768623737846352338915616287", "97019427096313354470198072370138828492" ], "threshold": 0.9 }, "signature_version": "v1", "signature_type": "Line", "deprecated": false } ] }