PT-2026-45419 · Gpac · Mp4Box

Published

2025-09-09

·

Updated

2026-06-01

·

CVE-2025-60495

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GPAC Project/MP4Box versions prior to 26.02.0
Description A segmentation violation occurs in the gf media get color info() function located in /media tools/isom tools.c due to pointer dereferencing. This allows an attacker to cause a Denial of Service (DoS) by providing a specially crafted data file.
Recommendations Update to version 26.02.0 or later.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07718
CVE-2025-60495

Affected Products

Mp4Box