Executive brief
A vulnerability exists in GPAC MP4Box, a widely used tool for processing and packaging multimedia files. By tricking a user into opening a specially crafted MP4 file, an attacker can cause the application to crash unexpectedly. This results in a denial of service, potentially disrupting media production workflows or automated processing pipelines.
Technical details
A NULL pointer dereference vulnerability exists in GPAC MP4Box v2.4 within the gf_media_map_esd function located in media_tools/isom_tools.c. The flaw is triggered when the application attempts to process a malformed MP4 file containing specific Elementary Stream Descriptor (ESD) configurations that the parser fails to validate. An attacker can exploit this by providing a crafted media file to a user or an automated system using MP4Box, leading to an immediate application crash (Denial of Service). This is a local attack vector requiring the victim to interact with the malicious file.
Affected products
- GPAC MP4Box 2.4
Timeline
- 2026-06-15: disclosed: Initial disclosure of CVE-2025-55649