Impact
A flaw exists in the GPAC MP4Box component's list.c utility, where the gf_list_count function can be used after freeing. When an attacker supplies crafted input, the function can access freed memory, resulting in a use-After-Free that may corrupt memory or crash the process. The problem is, but local memory corruption can enable partial or full compromise of the vulnerable system. This weakness is classed as CWE-119 and CWE-416.
Affected Systems
The vulnerability affects the GPAC MP4Box software distributed as the GPAC project. All versions prior to the patch commit 49dee5cad329cfed310c1682703df7daa47df31a (referenced by release abi-16.23) are susceptible. Systems that run GPAC for media processing or packaging should determine whether the installed binary matches the affected commit and plan to upgrade accordingly.
Risk and Exploitability
With a CVSS score of 4.8, the vulnerability is considered moderate. The EPSS score is < 1%, indicating, and the vulnerability is not listed in CISA's KEV catalog. Because the attack requires local access and the exploit has already been published, the risk to environments where GPAC processes untrusted input files is non-negligible. Prompt patching reduces the chance of exploitation.
OpenCVE Enrichment