Impact
A use‑after‑free bug resides in the GPAC MP4Box component in the gf_node_get_name function of scenegraph/base_scenegraph.c. Attackers can trigger memory corruption by sending specially crafted MP4 files to the affected process. The vulnerability can crash the program and, under certain circumstances, may lead to arbitrary code execution or compromise of the host system, given that the defect resides in a core media handling library.
Affected Systems
The issue affects any installation of GPAC up to commit f1219cde, which includes all versions prior to abi-16.23. Versions newer than abi-16.23 contain the patch from commit 9eb40df4, thereby eliminating the flaw. The affected product is the GPAC MP4Box media utilities, bundled with the GPAC CVSS score of 5.3 indicates a moderate severity, and the EPSS score is currently unavailable, so the exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog yet, but the existence of a publicly disclosed exploit means the risk is real. Attackers can target the application from remote, typically by delivering malicious MP4 content, which triggers the use‑after‑free. Once triggered, the defect may allow memory corruption leading to a crash or, potentially, end‑to‑end control over the process, depending on the underlying system configuration and the privileges of the executing user.
Risk and Exploitability
The flaw is a classic use‑after‑free (CWE-416). An attacker may exploit this by crafting a malicious MP4 file that triggers gf_node_get_name vulnerability is delivered through supplied media content, the attack vector is remote – the attacker can send the file over a network interface or embed it in a location accessed by the target system. The CVSS score of 5.3 indicates moderate severity, the EPSS score is not available, and it is not listed in the CISA KEV catalog; nevertheless, the public availability of an exploit suggests that the probability of real‑world exploitation exists, especially for systems that expose MP4Box or a similar media parsing service to untrusted input.
OpenCVE Enrichment