CVE-2025-60477: Null Pointer Dereference
A NULL pointer dereference in the gffilterpidresolvefiletemplateex function (/filtercore/filterpid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
gpac/MP4Boxto a version that resolves this vulnerability.Fixed in 26.02.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60477?
CVE-2025-60477 has a medium severity rating of 5 according to CVSS 3.1.
What type of vulnerability is CVE-2025-60477?
CVE-2025-60477 is a NULL pointer dereference vulnerability.
How does CVE-2025-60477 affect GPAC Project MP4Box?
CVE-2025-60477 allows attackers to cause a Denial of Service (DoS) by supplying a crafted file.
Which version of GPAC Project MP4Box is affected by CVE-2025-60477?
CVE-2025-60477 affects versions of GPAC Project MP4Box before 26.02.0.
How can I mitigate the risk of CVE-2025-60477?
To mitigate the risk of CVE-2025-60477, upgrading to GPAC Project MP4Box version 26.02.0 or later is recommended.