Impact
The vulnerability in GPAC’s MP4Box component, specifically in the vrml_tools.c file, triggers a null pointer dereference due to an unknown function. This flaw is characterized by CWE-476 and CWE-404 weaknesses. The resulting crash or instability occurs when the application processes malformed or crafted data. The CVSS score of 4.8 reflects a medium severity, and because the exploit path requires local interaction, the risk is limited to local users.
Affected Systems
GPAC versions up to the commit f1219cde are affected. The issue is resolved in release abi‑16.23, which incorporates the patch identified by commit 49dee5cad329cfed310c1682703df7daa47df31a. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The risk is confined to local users who can execute MP4Box, as the attack vector is local. With an EPSS score of less than 1% and no listing in CISA’s KEV catalog, the likelihood of exploitation is very low but still non‑negligible. Public disclosure and the available exploit mean that updating promptly mitigates the threat.
OpenCVE Enrichment