Impact
The vulnerability originates in the mpgviddmx_process function of GPAC's MPEG Video Reframer component, where malformed MPEG‑video streams trigger a heap‑based buffer overflow. This flaw is a classic buffer overflow (CWE‑119/122) that can be exploited remotely, potentially allowing memory corruption, arbitrary code execution, or denial of service.
Affected Systems
GPAC is affected in all releases older than commit f1219cde. Versions prior to abi‑16.23 contain the flaw, while the patch commit afca1f1181668d85941d51ed1adf647807d5d975 is incorporated in release abi‑16.23 and later, resolving the issue.
Risk and Exploitability
The EPSS score of <1% indicates that exploitation is currently very unlikely, and the vulnerability is not listed in the CISA KEV catalog. A public exploit has been disclosed and the flaw is remotely triggerable by delivering malicious MPEG video through the affected component. The CVSS score of 5.3 reflects moderate severity; if exploited, an attacker could gain code execution or crash the application. Because the vulnerability can be triggered without local privileges, administrators should consider remediation priority low to medium, depending on the exposure of the affected component.
OpenCVE Enrichment