Junglewise Threat Intelligence

CVE-2025-55642: GPAC MP4Box floating point exception in avidmx_process

CVE-2025-55642 · Severity: info · Published 2026-06-15

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC MP4Box, a widely used tool for processing and packaging multimedia files, contains a flaw that can cause the application to crash. By providing a specially crafted media file, an attacker could trigger a mathematical error that forces the program to terminate unexpectedly. This primarily impacts the availability of the tool during automated media processing workflows.

Technical details

A floating point exception (specifically a divide-by-zero error) exists in GPAC MP4Box v2.4 within the avidmx_process function located in isomedia/isom_write.c. The vulnerability is triggered when the application processes a malformed or specially crafted AVI file. An attacker can exploit this by providing a malicious file to be processed by MP4Box, leading to a denial-of-service (DoS) condition via application crash. This is a local attack vector requiring the user or an automated system to run the utility against the malicious input.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-15: disclosed: Initial NVD publication date

References

Related threats