Executive brief
GPAC MP4Box is a popular open-source tool used for processing and packaging multimedia files like MP4s. A security flaw has been identified where a specially crafted video file can cause the software to crash. This could lead to a denial of service, disrupting media processing workflows or applications that rely on this tool to handle user-uploaded content.
Technical details
A stack-based buffer overflow vulnerability exists in GPAC MP4Box v2.4 within the 'filein_process' function located in 'in_file.c'. The issue is triggered when the application processes a maliciously crafted MP4 file. An attacker can exploit this by providing a file that exceeds expected buffer boundaries during processing, leading to memory corruption. The primary impact is a crash of the application (Denial of Service). While the current report focuses on DoS, stack overflows can sometimes lead to arbitrary code execution depending on the environment and protections in place.
Affected products
- GPAC MP4Box 2.4
Timeline
- 2026-06-09: disclosed: Initial NVD publication date