Impact
A vulnerability exists in GPAC MP4Box’s xmt_parse_element function, where a crafted media file can trigger a reachable assertion, causing the tool to terminate unexpectedly. The flaw falls under CWE‑617 and results in a local denial‑of‑service scenario. The impact is limited to the host running MP4Box; no remote exploitation is possible according to the current description.
Affected Systems
The issue affects the GPAC suite, specifically the MP4Box component, in any release prior to the commit f1219cde. The vulnerability is fixed in version abi‑16.23, which incorporates the patch commit afca1f1181668d85941d51ed1adf647807d5d975.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score of 0.00119 (< 1%) shows a very low but non‑zero exploitation probability and the vulnerability is not listed in the CISA KEV catalog. The attack vector is limited to local execution; the tool must be run on the targeted machine, so the impact is confined to the local system. Since the exploit has been publicly disclosed, any local user who has access to MP4Box can trigger a crash by feeding a malicious media file, potentially disrupting services or denying access to legitimate processing.
OpenCVE Enrichment