CVE-2025-55658: Medium severity Gpac MP4Box vulnerability
GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gfopusparsepacketheader function (mediatools/avparsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Box v2.4from your environment.Uninstall or stop using GPAC MP4Box v2.4. Do not process untrusted MP4 files with this version until a vendor-supplied fix is available; remove the component from affected systems or replace it with a safe alternative.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55658?
CVE-2025-55658 has a medium severity rating of 6.5 according to the CVSS 3.1 scoring system.
What type of attack does CVE-2025-55658 facilitate?
CVE-2025-55658 facilitates a Denial of Service (DoS) attack through a crafted MP4 file.
What versions of Gpac MP4Box are affected by CVE-2025-55658?
CVE-2025-55658 affects Gpac MP4Box version 2.4.
How do I fix CVE-2025-55658?
To fix CVE-2025-55658, it is recommended to update to the latest version of Gpac MP4Box that addresses this vulnerability.
What function is responsible for the vulnerability in CVE-2025-55658?
The vulnerability in CVE-2025-55658 is due to a floating point exception in the gf_opus_parse_packet_header function.