The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avccomputepoc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
[ { "signature_type": "Function", "deprecated": false, "source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302", "signature_version": "v1", "target": { "function": "gf_avc_read_sps_bs_internal", "file": "src/media_tools/av_parsers.c" }, "digest": { "function_hash": "39295482979318475893292998550012608033", "length": 10192.0 }, "id": "CVE-2021-40570-02f95021" }, { "signature_type": "Line", "deprecated": false, "source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302", "signature_version": "v1", "target": { "file": "src/media_tools/av_parsers.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "162301846487824417085976151097850441387", "290865607641083795548660822562839751511", "36877859478553293821283680965112273961", "277556399151842539648333058950472107336" ] }, "id": "CVE-2021-40570-e7a12def" } ]