Impact
The vulnerability in GPAC's gf_node_activate_ex function allows an attacker to trigger a stack-based buffer overflow through crafted media content. The overflow corrupts the stack frame, potentially leading to memory corruption or a program crash. Because the flaw is local only, an attacker requires access to the system where GPAC processes media, and can exploit via locally crafted files or over a local network. integrity, and availability for the process. While the buffer overflow does not grant remote code execution, it can be used to crash the application or facilitate further escalation if additional vulnerabilities exist.
Affected Systems
GPAC, the open-source media framework, is affected. All versions up to commit f1219cde are vulnerable. The fix is available in release abi‑16.23, applied in commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24.
Risk and Exploitability
The CVSS score of 2.4 indicates low severity, and the exploitation probability is very low. The vulnerability is not listed in CISA KEV, so no known large scale attacks are reported. The flaw requires local execution, so exploitation depends on an attacker already having access to the target host and the ability to exploit demonstrates that the overflow can exploit or privileged escalation is known at this time.
OpenCVE Enrichment