Impact
The vulnerability is an assertion failure inside the function stbl_GetSampleInfos of GPAC’s MP4Box, triggered by malformed MP4 input. Failure of the assertion leads to an abort of the process, causing the application to crash. No evidence of code execution or privilege escalation is provided, so the primary consequence is service interruption for the local user running the program.
Affected Systems
All versions of GPAC before the commit that introduced the fix (f1219cde) are affected, including releases prior to abi‑16.23. The product in question is the MP4Box component of GPAC. Users on older builds that expose MP4Box to untrusted files are at risk.
Risk and Exploitability
The CVSS score of 4.8 indicates low to moderate severity. Exploitation requires local access; an attacker must supply a crafted MP4 file to trigger the assertion. Public exploits have already been released, but the EPSS score of <1% suggests a very low probability of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment