GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gfisomparsemovieboxesinternal due to improper return value handling of GFSKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.
[
{
"id": "CVE-2022-29340-08de3dfc",
"source": "https://github.com/gpac/gpac/commit/37592ad86c6ca934d34740012213e467acc4a3b0",
"digest": {
"function_hash": "204068561095793227767970056049160792601",
"length": 6455.0
},
"signature_type": "Function",
"deprecated": false,
"target": {
"function": "gf_isom_box_parse_ex",
"file": "src/isomedia/box_funcs.c"
},
"signature_version": "v1"
},
{
"id": "CVE-2022-29340-a080898f",
"source": "https://github.com/gpac/gpac/commit/37592ad86c6ca934d34740012213e467acc4a3b0",
"digest": {
"line_hashes": [
"208719525030907384854481309931149601407",
"262414055590553386709960339212000700456",
"287494547593792256990466025884189760229"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "src/isomedia/isom_intern.c"
},
"signature_version": "v1"
},
{
"id": "CVE-2022-29340-a80636b0",
"source": "https://github.com/gpac/gpac/commit/37592ad86c6ca934d34740012213e467acc4a3b0",
"digest": {
"function_hash": "301523011820018470228411233188860826431",
"length": 13880.0
},
"signature_type": "Function",
"deprecated": false,
"target": {
"function": "gf_isom_parse_movie_boxes_internal",
"file": "src/isomedia/isom_intern.c"
},
"signature_version": "v1"
},
{
"id": "CVE-2022-29340-e33b0f64",
"source": "https://github.com/gpac/gpac/commit/37592ad86c6ca934d34740012213e467acc4a3b0",
"digest": {
"line_hashes": [
"188659798654361141089446755525976142299",
"332096073280269677175276025375831051751",
"308736001611605449345004818850539433779",
"130047476379767080417330509558579352648",
"134413338311360461268850345585908468640"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "src/isomedia/box_funcs.c"
},
"signature_version": "v1"
}
]