PT-2026-44037 · Gpac · Mp4Box
Published
2026-05-27
·
Updated
2026-05-30
·
CVE-2025-70116
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GPAC MP4Box (affected versions not specified)
Description
A NULL pointer dereference occurs when parsing certain truncated MP4 files. An unknown or invalid stsd entry can lead to missing descriptor fields, such as codec, mime, or profile strings. Consequently, the
gf media map esd() function calls strlen() on a NULL pointer, resulting in a crash.Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mp4Box