Executive brief
GPAC MP4Box, a widely used tool for processing and packaging multimedia files, contains a flaw that can cause the application to crash. By providing a specially crafted media file, an attacker could trigger a mathematical error that forces the program to terminate unexpectedly. This primarily impacts the availability of the tool during automated media processing workflows.
Technical details
A floating point exception (specifically a divide-by-zero error) exists in GPAC MP4Box v2.4 within the avidmx_process function located in isomedia/isom_write.c. The vulnerability is triggered when the application processes a malformed or specially crafted AVI file. An attacker can exploit this by providing a malicious file to be processed by MP4Box, leading to a denial-of-service (DoS) condition via application crash. This is a local attack vector requiring the user or an automated system to run the utility against the malicious input.
Affected products
- GPAC MP4Box 2.4
Timeline
- 2026-06-15: disclosed: Initial NVD publication date