CVE-2025-60481: NULL Pointer Defence in GPAC/MP4Box via gf_odf_ac4_cfg_dsi_v1 on crafted AC-4 stam
A NULL pointer dereference in the gfodfac4cfgdsiv1 function (/odf/descriptors.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC Project/MP4Boxto a version that resolves this vulnerability.Fixed in 26.02.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60481?
The severity of CVE-2025-60481 is classified as medium with a CVSS score of 5.5.
What kind of vulnerability is CVE-2025-60481?
CVE-2025-60481 is a NULL pointer dereference vulnerability that can lead to a Denial of Service.
How does CVE-2025-60481 affect GPAC/MP4Box?
CVE-2025-60481 affects GPAC/MP4Box by allowing attackers to cause a Denial of Service through a crafted AC4 file.
How do I fix CVE-2025-60481?
To fix CVE-2025-60481, update GPAC/MP4Box to versions released after 26.02.0.
What is required for an attacker to exploit CVE-2025-60481?
An attacker needs to supply a specially crafted AC4 file to exploit CVE-2025-60481.