PT-2026-45416 · Gpac · Mp4Box

Published

2025-07-16

·

Updated

2026-06-02

·

CVE-2025-60483

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC Project/MP4Box versions prior to 26.02.0
Description A NULL pointer dereference exists in the gf ac4 pres b 4 back channels present() function within the /media tools/av parsers.c file. This issue allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted AC4 file.
Recommendations Update to version 26.02.0 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07713
CVE-2025-60483

Affected Products

Mp4Box