The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gfisomgetpaytcount function in hint_track.c, which allows attackers to cause a denial of service.
[ { "source": "https://github.com/gpac/gpac/commit/ad18ece95fa064efc0995c4ab2c985f77fb166ec", "deprecated": false, "digest": { "function_hash": "64669718982500005998952664897227464772", "length": 460.0 }, "target": { "file": "src/isomedia/hint_track.c", "function": "GetHintFormat" }, "id": "CVE-2021-40576-642b86cc", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://github.com/gpac/gpac/commit/ad18ece95fa064efc0995c4ab2c985f77fb166ec", "deprecated": false, "digest": { "line_hashes": [ "213132367431935810995875342538304866537", "69422952422666335137015309587630551427", "154475117685622613766551368937792949715", "247987700451396011635532392404281105653" ], "threshold": 0.9 }, "target": { "file": "src/isomedia/hint_track.c" }, "id": "CVE-2021-40576-e15d50ed", "signature_type": "Line", "signature_version": "v1" } ]