CVE-2025-55661: Heap-based Buffer Overflow in GPAC/MP4Box via gf_opus_parse_packet_header on crafted MP4 file with malformed Opus packet
A heap buffer overflow in the Opus audio stream parser component of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Box v2.4from your environment.Uninstall or discontinue use of GPAC MP4Box v2.4 until a vendor-supplied fix is available. Do not process untrusted or external MP4 files with this version.
- Compensating control
Prevent processing of untrusted MP4 files and/or Opus audio streams until a fix is available: restrict or quarantine MP4 file uploads at ingestion points, block or filter MP4 files that contain Opus streams, and run any required MP4Box processing in a sandboxed or isolated environment to limit impact from crafted files that could trigger the heap buffer overflow.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55661?
The severity of CVE-2025-55661 is medium, with a CVSS score of 5.5.
How do I fix CVE-2025-55661?
To fix CVE-2025-55661, update to the latest version of GPAC MP4Box where the vulnerability has been patched.
What type of vulnerability is CVE-2025-55661?
CVE-2025-55661 is a heap-based buffer overflow vulnerability in the Opus audio stream parser component of GPAC MP4Box.
What impact does CVE-2025-55661 have?
CVE-2025-55661 can lead to a Denial of Service (DoS) when an attacker supplies a crafted MP4 file.
Which software is affected by CVE-2025-55661?
CVE-2025-55661 affects GPAC MP4Box version 2.4.