Impact
A local buffer over-read flaw exists in the MP4Box component of GPAC, triggered during the gf_svg_attributes_copy function when processing a crafted SVG attribute. The vulnerability allows an attacker with local access to read beyond the intended buffer boundaries, potentially disclosing sensitive data stored in adjacent memory. The flaw is classified as a buffer over-read (CWE-119) and a read past the allocated limit (CWE-126).
Affected Systems
The issue affects GPAC versions up to the Git commit identified as f1219cde. Users running the MP4Box tool in these versions are at risk. The problem is fully resolved in the GPAC release tagged abi-16.23. The patch corresponding to the commit afca1f1181668d85941d51ed1adf647807d5d975 implements the necessary fix.
Risk and Exploitability
The CVSS score of 4.8 places this vulnerability in the moderate range. Exploit probability is not quantified by EPSS, and the flaw is not listed in the CISA KEV catalog. The attack vector requires local access, meaning it can be leveraged only by users who can run MP4Box or manipulate its input on the affected system. Publicly available exploits are documented, increasing the likelihood that a local attacker could successfully exploit the flaw if the system is not patched.
OpenCVE Enrichment