Impact
The vulnerability in GPAC MP4Box arises when the function lsr_exec_command_list processes certain input, causing a reachable assertion in the file laser/lsr_dec.c. This assertion failure indicates that an invalid condition can be triggered by crafted input. The immediate consequence is a denial of service of the MP4Box utility, and any downstream processes relying on it. The likely attack vector is a local user invoking MP4Box with malicious arguments, as the vulnerability requires local access to trigger the assertion.
Affected Systems
GPAC, the open-source multimedia framework, is impacted up through the commit identified by f1219cde, including all releases prior to abi-16.23. The affected component is the MP4Box tool. Users running any legacy GPAC build that has not incorporated the patch commit afca1f1181668d85941d51ed1adf647807d5d975 are susceptible.
Risk and Exploitability
The CVSS score of 2.4 places the defect in the low-severity range, reflecting that the control requires local user access and the outcome is limited to a crash rather than arbitrary code execution. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Nevertheless, local attackers who can invoke MP4Box with crafted parameters could trigger the assertion, forcing the service to stop. The lack of network exposure and the low severity reduce the urgency, yet the failure to validate input remains a concern. The likely attack vector is local execution of MP4Box with malicious input, as inferred from the description.
OpenCVE Enrichment