Executive brief
GPAC MP4Box, a widely used tool for processing and packaging multimedia files, is vulnerable to a memory handling error. By tricking a user into opening a specially crafted MP4 video file, an attacker can cause the application to crash. This results in a denial of service, potentially disrupting media processing workflows or automated video conversion pipelines.
Technical details
A heap buffer overflow exists in GPAC MP4Box v2.4 within the gf_isom_vp_config_new function located in isomedia/avc_ext.c. The vulnerability is triggered when the application processes a maliciously crafted MP4 file containing malformed video configuration data. An attacker can exploit this by providing a specially designed file to the MP4Box utility, leading to out-of-bounds memory access. Successful exploitation results in an application crash (Denial of Service). The attack requires the victim to process the malicious file locally.
Affected products
- GPAC MP4Box 2.4
Timeline
- 2026-06-15: disclosed: Initial publication of the CVE record.