CVE-2025-60483: NULL Pointer Defence in GPAC/MP4Box via gf_ac4_ps_b_4_back_channels_psent on crafted AC-4 stam
A NULL pointer dereference in the gfac4presb4backchannelspresent function (/mediatools/avparsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AC4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC Project/MP4Boxto a version that resolves this vulnerability.Fixed in 26.02.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60483?
The severity of CVE-2025-60483 is medium with a CVSS score of 5.5.
How do I fix CVE-2025-60483?
To fix CVE-2025-60483, update GPAC MP4Box to version 26.02.0 or later that addresses the NULL pointer dereference.
What type of vulnerability is CVE-2025-60483?
CVE-2025-60483 is a NULL pointer dereference vulnerability.
What could an attacker achieve by exploiting CVE-2025-60483?
An attacker could cause a Denial of Service (DoS) by exploiting CVE-2025-60483 through a crafted AC4 file.
In which version of GPAC MP4Box was CVE-2025-60483 found?
CVE-2025-60483 was found in GPAC MP4Box versions prior to 26.02.0.