Impact
A null pointer dereference occurs in the gf_node_list_get_child function of GPAC's MP4Box when the Target argument is manipulated. This flaw causes the application to crash, which can be triggered by an attacker supplying crafted input over a network. The vulnerability is classified as a memory management error (CWE‑476) and an unchecked return value issue (CWE‑404).
Affected Systems
All released versions of GPAC up to commit f1219cde, including the MP4Box component on any operating system where it is executed, are affected. The known fix is version abi‑16.23 or the patch commit afca1f1181668d85941d51ed1adf647807d5d975. If the environment runs older GPAC binaries or uses MP4Box as a server‑side tool, the vulnerability is present.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. Nevertheless, the threat is real because a public exploit exists and the attack vector is remote with no authentication required. The impact is limited to application denial of service, which could disrupt processing pipelines or media servers but does not grant code execution or data disclosure. This vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment