PT-2026-45416 · Gpac · Mp4Box
Published
2025-07-16
·
Updated
2026-06-02
·
CVE-2025-60483
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GPAC Project/MP4Box versions prior to 26.02.0
Description
A NULL pointer dereference exists in the
gf ac4 pres b 4 back channels present() function within the /media tools/av parsers.c file. This issue allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted AC4 file.Recommendations
Update to version 26.02.0 or later.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mp4Box