PT-2025-2881 · Gpac+2 · Gpac+2

Frank-Z7

·

Published

2025-01-23

·

Updated

2025-04-30

·

CVE-2024-50664

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gpac version 2.4
Description The issue is a heap-buffer-overflow in the gpac/MP4Box module, specifically at isomedia/sample descs.c:1799 in the gf isom new mpha description function.
Recommendations For gpac version 2.4, as a temporary workaround, consider disabling the gf isom new mpha description function until a patch is available. Restrict access to the gpac/MP4Box module to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-07587
CVE-2024-50664

Affected Products

Debian
Red Os
Gpac