Impact
A null pointer dereference occurs in the gf_media_export_webvtt_metadata function when the argument Name is manipulated. The vulnerability leads to a local crash of the GPAC media export process, effectively denying service to the impacted user or process.
Affected Systems
The flaw affects GPAC versions up to 2.4.0. The product is the GPAC media framework, with no specific sub‑releases identified beyond the 2.4.0 upper bound.
Risk and Exploitability
The CVSS score is 4.8, reflecting a medium severity impact. The EPSS score is underspecified as less than 1 %, indicating a low likelihood of exploitation. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attacks require local access to the affected system, yet publicly available exploit code exists. In practice, the risk is a moderate local denial of service with a low probability of occurrence.
OpenCVE Enrichment