Description
A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
Published: 2026-07-01
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pin::DecideBufferSize routine of the MPC‑BE media player developed by Aleksoid1978. When a crafted MP4 file triggers the flaw, the player attempts to compute a buffer size using an expression that results in a division‑by‑zero error, causing the application to crash. The weakness is classified as CWE‑369 and results in a loss of service availability without exposing data or privileges.

Affected Systems

Any installation of MPC‑BE built before commit 4341cb3 contains the vulnerable buffer‑size calculation. Any installation of MPC‑BE that has not applied this commit is susceptible when parsing MP4 files.

Risk and Exploitability

The flaw is exposed by opening or streaming a malicious MP4 file, making delivery channel such as local disk, removable media, or network streams. Exploitation requires user action to play the file; no remote code execution is possible. The EPSS score is below 1%, indicating a low but non‑zero chance of exploitation, and the CVSS score of 5.5 reflects moderate severity. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 17, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MPC‑BE to commit 4341cb3 or newer, which removes the division‑by‑zero flaw.
  • If an upgrade cannot be performed immediately, quarantine untrusted MP4 files from the vulnerable player by disabling MP4 playback.
  • possible, run the media player inside a sandbox or with restricted user privileges to limit the impact of a crash.

Generated by OpenCVE AI on July 17, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Vulnerability in MPC‑BE MP4 Parsing Allows DoS

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Buffer‑Size Calculation Enables Denial of Service

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Buffer‑Size Calculation Enables Denial of Service

Mon, 13 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Division-by-Zero in MPC‑BE MP4 Parsing

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Division-by-Zero in MPC‑BE MP4 Parsing

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE MP4 Buffer Size Calculation Causes DoS

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE MP4 Buffer Size Calculation Causes DoS

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Vulnerability in MPC-BE Buffer-Size Calculation Enables Denial of Service

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Vulnerability in MPC-BE Buffer-Size Calculation Enables Denial of Service

Mon, 06 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Buffer Size Bug Causes DoS in MPC-BE

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Buffer Size Bug Causes DoS in MPC-BE

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in Media Player Classic – Basic Edition Leads to DoS via Malicious MP4

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in Media Player Classic – Basic Edition Leads to DoS via Malicious MP4

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE Buffer Size Calculation Causes Denial of Service

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE Buffer Size Calculation Causes Denial of Service

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in MPC-BE MP4 Parsing Leads to DoS

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in MPC-BE MP4 Parsing Leads to DoS

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Causing DoS via Malicious MP4
Weaknesses CWE-369

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Causing DoS via Malicious MP4
Weaknesses CWE-369

Wed, 01 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-02T14:40:28.915Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36911

cve-icon Vulnrichment

Updated: 2026-07-02T14:39:58.973Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T13:30:04Z

Weaknesses