Impact
A local heap-based buffer overflow occurs inside the gf_node_get_field routine of GPAC's MP4Box component. The flaw is triggered by malicious input that causes the function to write beyond the bounds of a heap buffer, resulting in CWE-119 and CWE-122 and can lead to crashes or altered program behavior, although arbitrary code execution is not guaranteed by the description.
Affected Systems
GPAC releases up to commit f in scenegraph/base_scenegraph.c, are affected. All installations running a version earlier than abi-16.23 are susceptible. The official fix is delivered by the patch commit 49dee5cad329cfed310c1682703df7daa47df31a, incorporated in the abi-16.23 release.
Risk and Exploitability
The CVSS base score of 4.8 indicates a moderate severity. The EPSS score is less than 1%, showing that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local, with crafted input. Because the exploitation is possible only on systems that run the vulnerable component, the overall risk remains moderate but timely remediation is still recommended.
OpenCVE Enrichment