The gfbswrite_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.
{ "vanir_signatures": [ { "id": "CVE-2021-40606-00ec9c94", "signature_type": "Function", "target": { "file": "src/utils/os_config_init.c", "function": "gf_cfg_init" }, "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "digest": { "function_hash": "331609225902553284938660782849123559724", "length": 2924.0 }, "deprecated": false, "signature_version": "v1" }, { "id": "CVE-2021-40606-84a001c2", "signature_type": "Line", "target": { "file": "src/utils/os_config_init.c" }, "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "digest": { "threshold": 0.9, "line_hashes": [ "253854454906731252594870579307233588965", "179864446493625039430457959093405636565", "157047988769606476955262936216865999399", "25205688373900634743508465492002274847" ] }, "deprecated": false, "signature_version": "v1" }, { "id": "CVE-2021-40606-abddd526", "signature_type": "Function", "target": { "file": "applications/mp4client/main.c", "function": "PrintUsage" }, "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "digest": { "function_hash": "116287927203832314234354772323596679187", "length": 1136.0 }, "deprecated": false, "signature_version": "v1" }, { "id": "CVE-2021-40606-dde39a3b", "signature_type": "Line", "target": { "file": "applications/mp4client/main.c" }, "source": "https://github.com/gpac/gpac/commit/418db4149af78773815b5f6a7030a120037ba140", "digest": { "threshold": 0.9, "line_hashes": [ "110287411499135302499254568127786275886", "196881605958314966606044579045527764763", "211928352066196418331258856473204866912", "280195963159516847825224043850516008460" ] }, "deprecated": false, "signature_version": "v1" } ] }