Memory leak in the infeboxread function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted file.
{ "vanir_signatures": [ { "target": { "file": "src/isomedia/box_code_meta.c", "function": "infe_box_read" }, "digest": { "length": 1558.0, "function_hash": "190621662993771390952759254767544999659" }, "id": "CVE-2021-33363-8a710907", "signature_version": "v1", "deprecated": false, "signature_type": "Function", "source": "https://github.com/gpac/gpac/commit/ec64c7b8966d7e4642d12debb888be5acf18efb9" }, { "target": { "file": "src/isomedia/box_code_meta.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "181656743207928008313595382899266825553", "14420871732517230207540520586412872457", "278624330078857265765932513339803816499", "231074979996065217382359061034165557310", "325610805991539989549438125502161135907", "276709810274072504270466193742067157565", "277018454457004809969067120013534220047" ] }, "id": "CVE-2021-33363-93c1c670", "signature_version": "v1", "deprecated": false, "signature_type": "Line", "source": "https://github.com/gpac/gpac/commit/ec64c7b8966d7e4642d12debb888be5acf18efb9" } ] }