Impact
A null pointer dereference occurs in the ctts_box_write function of GPAC MP4Box v2.4. An attacker can supply a specifically crafted MP4 file that triggers a crash in the media processing routine, causing the application to become non‑responsive. The outcome is a denial of service that can affect any system component that relies on MP4Box for media handling.
Affected Systems
The vulnerability is present only in the GPAC MP4Box v2.4 distribution. No other vendors or product versions are listed as affected, so the impact is limited to installations running that exact version.
Risk and Exploitability
EPSS metric is not available, so the severity is quantified by a CVSS score of 6.5. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. The flaw can be triggered by delivering a crafted MP4 file to the application, so environments that process user‑supplied media without isolation are at higher risk. The attack vector is likely to be local or remote entry through file upload, download, or network‑exposed media services that invoke MP4Box, although the description does not specify the exact exposure; defenders should assume any untrusted MP4 can be processed.
OpenCVE Enrichment