Heap Buffer Overflow in GPAC MP4Box Product by GPAC
CVE-2025-55652

5.5MEDIUM

Key Information:

Vendor

GPAC

Vendor
CVE Published:
15 June 2026

What is CVE-2025-55652?

A vulnerability exists in the GPAC MP4Box v2.4 due to a heap buffer overflow in the gf_isom_vp_config_new function. Attackers can exploit this flaw by crafting a specific MP4 file that, when processed, could lead to a Denial of Service, impacting the availability of the affected system.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.