CVE-2021-30015 log

Source
Severity Low
Remote Yes
Type Denial of service
Description
There is a null pointer dereference in function filter_core/filter_pck.c:gf_filter_pck_new_alloc_internal in GPAC 1.0.1. The pid comes from function av1dmx_parse_flush_sample, the ctx.opid may be NULL. The result is a crash in gf_filter_pck_new_alloc_internal.
Group Package Affected Fixed Severity Status Ticket
AVG-1823 gpac 1:1.0.1-1 Medium Vulnerable
References
https://github.com/gpac/gpac/issues/1719
https://github.com/gpac/gpac/files/6219469/bug2.zip
https://github.com/gpac/gpac/commit/13dad7d5ef74ca2e6fe4010f5b03eb12e9bbe0ec