PT-2025-30079 · Gpac+3 · Gpac+3

Cybergym

·

Published

2025-07-18

·

Updated

2025-10-03

·

CVE-2025-7797

CVSS v4.0

5.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions GPAC versions up to 2.4
Description A null pointer dereference issue exists in the gf dash download init segment function within the src/media tools/dash client.c file. Manipulation of the base init url argument can trigger this issue. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Apply the patch identified as 153ea314b6b053db17164f8bc3c7e1e460938eaa.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-11267
CVE-2025-7797

Affected Products

Astra Linux
Debian
Gpac
Red Os