CVE-2025-52293: Out-of-bounds ad in GPAC/MP4Box via gf_hevc_ad_sps_bs_internal on crafted HEVC SPS in MP4 file
A segmentation violaton in the gfhevcreadspsbsinternal function (mediatools/avparsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Box v2.4from your environment.Uninstall or stop using GPAC MP4Box v2.4 until a vendor-supplied patch or fixed version is made available.
- Compensating control
Avoid processing untrusted MP4 files that contain HEVC SPS data; if processing such files is required, do so in a sandboxed or isolated environment to mitigate potential Denial of Service from crafted SPS data.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52293?
The severity of CVE-2025-52293 is high, with a CVSS score of 7.5.
How do I fix CVE-2025-52293?
To fix CVE-2025-52293, ensure you update GPAC MP4Box to the latest version that addresses this vulnerability.
What is the impact of CVE-2025-52293?
CVE-2025-52293 may allow attackers to cause a Denial of Service (DoS) through crafted HEVC SPS data.
Which software is affected by CVE-2025-52293?
CVE-2025-52293 affects GPAC MP4Box version 2.4.
What type of vulnerability is CVE-2025-52293?
CVE-2025-52293 is a segmentation violation vulnerability.