Impact
Pin::DecideBufferSize routine of the MPC‑BE media player developed by Aleksoid1978. When a crafted MP4 file triggers the flaw, the player attempts to compute a buffer size using an expression that results in a division‑by‑zero error, causing the application to crash. The weakness is classified as CWE‑369 and results in a loss of service availability without exposing data or privileges.
Affected Systems
Any installation of MPC‑BE built before commit 4341cb3 contains the vulnerable buffer‑size calculation. Any installation of MPC‑BE that has not applied this commit is susceptible when parsing MP4 files.
Risk and Exploitability
The flaw is exposed by opening or streaming a malicious MP4 file, making delivery channel such as local disk, removable media, or network streams. Exploitation requires user action to play the file; no remote code execution is possible. The EPSS score is below 1%, indicating a low but non‑zero chance of exploitation, and the CVSS score of 5.5 reflects moderate severity. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment