Impact
Based on the description, it is inferred that manipulating the input processed by gf_sm_dump_command_list could trigger the assertion failure and cause the function to crash. The resulting crash produces a denial‑of‑service condition for any user or process running MP4Box on the affected system. This flaw does not provide remote code execution, escalated privileges, or data disclosure; it is limited to local denial of service.
Affected Systems
All releases of GPAC MP4Box up to commit f1219cde are affected. The issue is fixed starting with the abi‑16.23 release, which applies the commit identified by afca1f1181668d85941d51ed1adf647807d5d975. Systems running older versions of GPAC, particularly those that use MP4Box, should be considered vulnerable if they have not applied the patch or updated to abi‑16.23.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium risk level, and the EPSS score is less than 1%, while the vulnerability is not listed in CISA’s KEV catalog. The flaw requires a local attacker with the ability to execute MP4Box to exploit the assertion failure, and the exploit is publicly available and might be used where privileged or local users have access to run MP4Box. The threat is limited to denial of service rather than more serious compromise.
OpenCVE Enrichment