A Segmentation fault caused by null pointer dereference vulnerability eists in Gpac through 1.0.2 via the avcparseslice function in av_parsers.c when using mp4box, which causes a denial of service.
[ { "source": "https://github.com/gpac/gpac/commit/cf6771c857eb9a290e2c19ddacfdd3ed98b27618", "deprecated": false, "digest": { "line_hashes": [ "33139317742673087143301621788696875760", "40067023463941325579072277044494246212", "6858436001336251329503023834040476408", "215858056015409008606797735826477519635", "280664615792475706385971753107292148226", "285671375156926123525445493399398643339", "223018829820854772209840817076401493095", "218324005861058336068488887534003891768", "277825195111491555614094537885684252686", "256195421321412857773894656983395858737" ], "threshold": 0.9 }, "target": { "file": "src/media_tools/av_parsers.c" }, "id": "CVE-2021-40564-021e478c", "signature_type": "Line", "signature_version": "v1" }, { "source": "https://github.com/gpac/gpac/commit/cf6771c857eb9a290e2c19ddacfdd3ed98b27618", "deprecated": false, "digest": { "function_hash": "242501853663965271778312182443974469698", "length": 733.0 }, "target": { "file": "src/media_tools/av_parsers.c", "function": "gf_bs_read_ue_log_idx3" }, "id": "CVE-2021-40564-27059077", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://github.com/gpac/gpac/commit/cf6771c857eb9a290e2c19ddacfdd3ed98b27618", "deprecated": false, "digest": { "function_hash": "116652901503841662658803101052099390509", "length": 4231.0 }, "target": { "file": "src/media_tools/av_parsers.c", "function": "avc_parse_slice" }, "id": "CVE-2021-40564-a254b421", "signature_type": "Function", "signature_version": "v1" } ]