Denial of Service Vulnerability in GPAC Project's MP4Box
CVE-2025-60477
5MEDIUM
What is CVE-2025-60477?
A vulnerability exists in GPAC Project's MP4Box due to a NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function. This flaw allows attackers to craft a specific file that triggers a Denial of Service, causing the application to crash or become unresponsive. Users should update to versions released after 26.02.0 to mitigate this risk.
