Impact
A double free flaw resides in the gf_isom_nalu_sample_rewrite routine of the GPAC MP4Box tool. Manipulation of the nalu_out_bs argument causes the routine to release the same memory block twice, corrupt corruption can trigger a crash or, under the right conditions, lead to unintended code execution, although the archived description does not confirm a remote code‑execution vector. The issue is categorized under the memory corruption weaknesses of CWE‑119 and the double‑free weakness of CWE‑415.
Affected Systems
Every build of the GPAC MP4Box utility up to and including the 2.5‑DEV release series incorporates the vulnerable source file. Users who run these versions and process media files that originate from untrusted or potentially malicious sources are exposed.
Risk and Exploitability
The CVSS score of 4.8 indicates a low overall severity, while the EPSS reading of less than 1% suggests exploitation is unlikely in the broader environment. Compromise requires local execution of MP4Box or a similar file, making the attack surface limited to the local host. The flaw is not listed in the CISA KEV catalog, but proof‑of‑concept exploits are publicly available, which increases the practical risk for an attacker who can reach the target system.
OpenCVE Enrichment