Impact
The issue is a memory corruption flaw in the gf_bt_report function of the MP4Box component in GPAC. The flaw can be triggered remotely, allowing an attacker to overwrite memory and potentially gain arbitrary code execution or crash the process. The vulnerability is identified as CWE‑119, which signifies improper handling of a buffer boundary.
Affected Systems
The flaw affects all GPAC releases up to the commit identified by f1219cde, which includes versions prior to abi‑16.23. Users running MP4Box on any of these versions should be aware that the vulnerability exists.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is <1%, indicating a low probability of exploitation, but the public exploit suggests that the vulnerability can still be targeted. The flaw is not listed in the CISA KEV catalog. An attacker can exploit the issue remotely by supplying crafted input to the MP4Box tool, and because the memory corruption could lead to arbitrary code execution, the risk to confidentiality, integrity, and availability is high. The remote nature of the attack vector emphasizes the need for timely remediation.
OpenCVE Enrichment