PT-2026-44037 · Gpac · Mp4Box

Published

2026-05-27

·

Updated

2026-05-30

·

CVE-2025-70116

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GPAC MP4Box (affected versions not specified)
Description A NULL pointer dereference occurs when parsing certain truncated MP4 files. An unknown or invalid stsd entry can lead to missing descriptor fields, such as codec, mime, or profile strings. Consequently, the gf media map esd() function calls strlen() on a NULL pointer, resulting in a crash.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-70116

Affected Products

Mp4Box