Impact
The flaw is a use‑after‑free bug in the gf_sg_script_load function located in scenegraph/vrml_tools.c of GPAC’s MP4Box component. After a script is loaded and the memory that holds it is freed, the function can still reference that memory, allowing an attacker to execute arbitrary code or crash the application. The weakness is a typical buffer overflow and memory corruption scenario (CWE‑119 and CWE‑416). The vulnerability is remotely exploitable, and a public exploit is available.
Affected Systems
GPAC, the open‑source multimedia framework that includes the MP4Box command‑line tool. Versions up to the Git commit f1219cde are vulnerable. The advised fix is to upgrade to version abi‑16.23 or later, which incorporates the patch from commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. No EPSS score is published, and the flaw is not listed in the CISA KEV catalog. Because the attack requires only a remotely triggered manipulation of a script, the practical exploitation is realistic, especially since a proof‑of‑concept and public exploit code have already been released.
OpenCVE Enrichment