CVE-2025-60486: Use-After-Fe in GPAC/MP4Box via dasher_process on crafted MPEG-2 TS file
A heap use-after-free in the dasherprocess function (/filters/dasher.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC Project/MP4Boxto a version that resolves this vulnerability.Fixed in 26.02.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60486?
The severity of CVE-2025-60486 is classified as medium with a CVSS score of 5.5.
How does CVE-2025-60486 affect GPAC/MP4Box?
CVE-2025-60486 affects GPAC/MP4Box by allowing attackers to cause a Denial of Service by supplying a crafted MPEG-2 TS file.
What type of vulnerability is CVE-2025-60486?
CVE-2025-60486 is a Use-After-Free vulnerability that occurs in the dasher_process function of GPAC/MP4Box.
How can I mitigate CVE-2025-60486?
Mitigation for CVE-2025-60486 involves updating GPAC/MP4Box to a version released after February 26, 2020.
What is the potential impact of CVE-2025-60486?
The potential impact of CVE-2025-60486 is a Denial of Service, which can disrupt the availability of the application.