Impact
The flaw is a null pointer dereference in the gf_sg_mfurl_del routine of GPAC MP4Box’s scenegraph module. This defect can cause the application to crash or terminate unexpectedly when the function is invoked with a malformed or absent URL reference. The attack does not provide code execution but destroys process integrity, potentially denying service to legitimate users. The associated weaknesses are identified as CWE-476 (Null Pointer Dereference) and CWE-404 (Broken or Missing Functionality).
Affected Systems
GPAC, particularly the MP4Box component that includes the scenegraph f1219cde are affected; the vendor does not assign specific major/minor numbers due to its rolling release model23 release, which incorporates the patch with identifier 49dee5cad329cfed310c1682703df7daa47df31a, will remove the vulnerability.
Risk and Exploitability
The vulnerability bears a CVSS score of 4.8, EPSS score of < 1%, and is not listed in the CISA KEV catalog. However, the exploit is publicly available and might be used, indicating a potential risk of exploitation in environments where the attacker can run the MP4Box tool locally. Local access is required, so the attack vector is inferred to be local or within an environment where the attacker can run the MP4Box tool. Exploitation would trigger a denial of service condition but would not breach confidentiality or integrity.
OpenCVE Enrichment