CVE-2025-52292: Stack-based Buffer Overflow in GPAC/MP4Box via filein_process on crafted MP4 file during DASH segmentation
A stack buffer overflow in the fileinprocess function (infile.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Box v2.4from your environment.Uninstall GPAC MP4Box v2.4 or stop using the MP4Box v2.4 binary until a vendor-supplied fix is available.
- Compensating control
Do not process untrusted MP4 files. Restrict ingestion of MP4 files, and if processing is required, run MP4Box in a sandboxed or isolated environment (container or limited-privilege VM) to mitigate potential DoS from crafted MP4 files.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52292?
CVE-2025-52292 has a critical severity rating of 7.5 according to the CVSS 3.1 metrics.
How do I fix CVE-2025-52292?
To fix CVE-2025-52292, update to the latest version of GPAC MP4Box that includes the patch for the stack-based buffer overflow.
What exploit does CVE-2025-52292 take advantage of?
CVE-2025-52292 exploits a stack-buffer overflow in the filein_process function during the processing of crafted MP4 files.
What potential impact does CVE-2025-52292 have?
The impact of CVE-2025-52292 includes potential Denial of Service (DoS) when a vulnerable version of MP4Box processes a maliciously crafted MP4 file.
Which software is affected by CVE-2025-52292?
CVE-2025-52292 affects GPAC MP4Box version 2.4.