CVE-2025-55645: Buffer Overflow
A heap buffer overflow in the gfcencsetpssh function (isomedia/drmsample.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Box v2.4from your environment.Uninstall or stop using GPAC MP4Box v2.4 until a vendor fix is available. Do not process untrusted or externally sourced MP4 files with this version.
- Compensating control
Prevent or limit exposure to crafted MP4 files: block or quarantine untrusted MP4 uploads, run MP4Box in an isolated sandbox or VM with strict resource limits, and restrict which users/systems may feed files to MP4Box v2.4 to mitigate denial-of-service risk.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55645?
The severity of CVE-2025-55645 is rated as medium with a CVSS score of 5.5.
How do I fix CVE-2025-55645?
To fix CVE-2025-55645, update Gpac MP4Box to the latest version where the vulnerability has been addressed.
What type of vulnerability is CVE-2025-55645?
CVE-2025-55645 is classified as a heap buffer overflow vulnerability.
What impact does CVE-2025-55645 have?
CVE-2025-55645 can potentially lead to a Denial of Service (DoS) when a crafted MP4 file is processed.
In which component is CVE-2025-55645 found?
CVE-2025-55645 is found in the gf_cenc_set_pssh function of the GPAC MP4Box software.