CVE-2025-60485: NULL Pointer Defence in GPAC/MP4Box via gf_isom_apple_set_tag_ex on crafted MP4 with corrupted esds box
A segmentation violation in the gfisomapplesettagex function (/isomedia/isomwrite.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC Project/MP4Boxto a version that resolves this vulnerability.Fixed in 26.02.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60485?
CVE-2025-60485 has a medium severity level with a CVSS score of 5.5.
What is the risk associated with CVE-2025-60485?
The risk associated with CVE-2025-60485 is classified as 33.
How do I fix CVE-2025-60485?
To fix CVE-2025-60485, update to GPAC/MP4Box version 26.02.0 or later where the vulnerability is addressed.
What type of vulnerability is CVE-2025-60485?
CVE-2025-60485 is a Null Pointer Dereference vulnerability leading to a Denial of Service.
How can an attacker exploit CVE-2025-60485?
An attacker can exploit CVE-2025-60485 by supplying a crafted MP4 file that triggers a segmentation violation.