CVE-2025-7797: GPAC dash_client.c gf_dash_download_init_segment null pointer dereference
A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gfdashdownloadinitsegment of the file src/mediatools/dashclient.c. The manipulation of the argument baseiniturl leads to null pointer dereference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 153ea314b6b053db17164f8bc3c7e1e460938eaa. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPACto a version that resolves this vulnerability.Fixed in 2.4Patch 153ea314b6b053db17164f8bc3c7e1e460938eaa
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7797?
CVE-2025-7797 has been rated as problematic, indicating a significant vulnerability in the software.
How do I fix CVE-2025-7797?
To fix CVE-2025-7797, update GPAC to version 2.5 or later, where the vulnerability has been addressed.
What is affected by CVE-2025-7797?
CVE-2025-7797 affects GPAC versions up to and including 2.4, particularly in the function gf_dash_download_init_segment.
What type of vulnerability is CVE-2025-7797?
CVE-2025-7797 is a null pointer dereference vulnerability, which can lead to crashes and potential exploitation.
Is CVE-2025-7797 remotely exploitable?
Yes, CVE-2025-7797 may be remotely exploitable, depending on the application's usage and exposure.