PT-2026-3089 · Gpac · Gpac

Published

2025-01-01

·

Updated

2026-01-17

·

CVE-2025-70303

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC version 2.4.0
Description A heap overflow exists in the uncv parse config() function when processing a specially crafted MP4 file. This can lead to a Denial of Service (DoS).
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to or avoiding the processing of untrusted MP4 files until a patch is available.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-70303

Affected Products

Gpac