Impact
The flaw exists in the gf_node_get_field_count function of the GPAC attacker can craft input that causes the function to trigger an assertion failure, terminating the process. This results in a local denial of service because the program crashes and is an unchecked input handling flaw identified by CWE-617.
Affected Systems
Affected products are the GPAC software suite, specifically the MP4Box component, in all releases up to the commit identifier f1219cde. The security fix is available in version abi-16.23, which incorporates the patch identified by commit 49dee5cad329cfed310c1682703df7daa47df31a. Devices or systems running earlier versions are vulnerable.
Risk and Exploitability
The CVSS score of 2.4 indicates low severity. The EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA KEV. An attacker with local access can trigger the assertion by supplying crafted input to gf_node_get_field_count, causing a crash and local denial of service. No escalation or data compromise occurs.
OpenCVE Enrichment