Impact
This flaw occurs in the GPAC TeXML File Handler’s txtin_probe_duration function in src/filters/load_text.c, where a manipulated txml_timescale argument causes a divide‑by‑zero error. The resulting crash disables GPAC during TeXML file processing, leading to a service interruption for the local user or application that invoked the handler. The weakness is classified as CWE-369 and reflects improper error handling (CWE-404).
Affected Systems
Only the GPAC build 26.03-DEV-rev342-g80071f700-master is known to be affected; no other vendors or product lines are listed.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of less than 1 % signals a low likelihood of exploitation. Because the attack requires local host access, an attacker must have sufficient privilege to supply a. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment