Impact
The flaw is a stack-based buffer overflow in the gf_sg_dom_event_bubble function of the MP4Box component in GPAC version 26.07.0. When this function processes specially crafted input, the buffer is overrun, potentially allowing an attacker to overwrite the stack and execute arbitrary code or crash the process. The vulnerability is classified as local, requiring the attacker to have access to the environment in which MP4Box runs.
Affected Systems
It affects the GPAC project’s MP4Box utility. The issue exists in the 26.07.0 release and has been fixed in the abi-16.23 release. The patch identifier is 9eb40df4448b88d6a6ce3454657c06f47eff0b24.PE the vulnerable version.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. EPSS Score is below 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Since the exploit is local only, the risk is limited to users who can run MP4Box with untrusted data. The stack overflow could lead to code execution or denial of service if an attacker controls but could be high if local privilege is available. The publicly disclosed exploit means the vulnerability can be used if the local environment is compromised.
OpenCVE Enrichment