Impact
A segmentation violation occurs in the gf_isom_apple_set_tag_ex function within isom_write.c of GPAC Project/MP4Box. This defect causes an unhandled crash when the tool processes a specially crafted MP4 file, resulting in a denial of service. The fault stems from an out‑of‑bounds memory access that corrupts the executing process's state.
Affected Systems
The vulnerability affects the GPAC Project’s MP4Box utility for all releases older than 26.02.0. Systems that rely on MP4Box for media processing—such as media servers, content creation pipelines, or embedded devices—are potentially impacted.
Risk and Exploitability
No EPSS data is available and the flaw is not listed in the CISA KEV catalog. The CVSS score is unspecified, but the vulnerability can be triggered by feeding a crafted MP4 file to MP4Box, either locally or via a network interface. An attacker with the ability to supply such files can cause the application to crash, denying legitimate users access until the service is restarted.
OpenCVE Enrichment