Impact
A stack buffer overflow has been identified in the filein_process function of GPAC MP4Box v2.4, which is triggered when parsing a maliciously crafted MP4 file. The overflow corrupts the stack of the MP4Box process and causes it to crash, resulting in a denial of service. No code execution or remote access capabilities are described, so the flaw does not enable arbitrary execution of attacker supplied code.
Affected Systems
The vulnerability resides in GPAC MP4Box version 2.4. No other affected versions or additional product lines are listed. Consequently, any installation of MP4Box v2.4 that processes MP4 content is potentially impacted, while newer releases without this flaw are not mentioned as affected.
Risk and Exploitability
The CVSS score of 7.5 signals a high severity, but the EPSS score is unavailable and the vulnerability is not included in the CISA KEV catalog, implying limited evidence of active exploitation. Attackers would need to supply a crafted MP4 file to the MP4Box tool – a scenario typical in multimedia processing pipelines or manual media manipulation – to trigger the crash and disrupt service availability.
OpenCVE Enrichment