Impact
GPAC, an open‑source multimedia framework, has a vulnerability in its DVB‑MPE processing component that allows an attacker to execute arbitrary code. The flaw exists in the descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() functions where improper handling of input data can lead to code injection via malformed descriptors (CWE‑94). When triggered, the attacker can run malicious code with the privileges of the GPAC process, effectively compromising the host system.
Affected Systems
Any installation of GPAC built from source or distributed binaries prior to commit 0e4093392e1f847c90d20e031e893cd942fef938, which introduced the fix. No vendor product list is available in the CNA data, so the affected systems are any GPAC installations before that commit.
Risk and Exploitability
The CVSS score of 8.4 denotes a high severity risk for arbitrary code execution. The EPSS score is reported as less than 1%, indicating that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. Attacks require a specially crafted media payload delivered to a system running GPAC, either locally or via a network channel; the flaw does not rely on unauthenticated network services but can be exploited once the file is processed.
OpenCVE Enrichment