PT-2026-43373 · Mp4Box+1 · Mp4Box+1
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GPAC versions prior to 2.4.1
Description
A security flaw in the MP4Box component allows for a null pointer dereference, which occurs when the
MergeFragment() function in the src/isomedia/isom intern.c file is manipulated. This issue requires local access to be exploited.Recommendations
Apply patch 525bf1af642c30af04e4df5345e6d798c0a4d8a1 to resolve the issue.
As a temporary workaround, restrict access to the
MergeFragment() function within the MP4Box component to minimize the risk of exploitation.Exploit
Fix
NULL Pointer Dereference
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gpac
Mp4Box