CVE-2025-60495: NULL Pointer Defence in GPAC/MP4Box via gf_media_get_color_info on crafted MP4 with inconsistent sample entry
A segmentation violation in the gfmediagetcolorinfo function (/mediatools/isomtools.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted data file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC Project/MP4Boxto a version that resolves this vulnerability.Fixed in 26.02.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60495?
The severity of CVE-2025-60495 is medium with a CVSS score of 5.5.
What type of vulnerability is CVE-2025-60495?
CVE-2025-60495 is a Null Pointer Dereference vulnerability in the GPAC/MP4Box software.
How do I fix CVE-2025-60495?
To fix CVE-2025-60495, update your GPAC/MP4Box software to a version published after 26.02.0.
What impact does CVE-2025-60495 have on systems?
CVE-2025-60495 can lead to a Denial of Service (DoS) condition when exploited.
What is the affected function in CVE-2025-60495?
The affected function in CVE-2025-60495 is gf_media_get_color_info in the isom_tools.c file.