https://seclists.org/oss-sec/2026/q2/1044: CVE-2025-60474: Heap-based Buffer Overflow in GPAC/MP4Box via gf_media_import on crafted MPEG-2 TS file
Published Jun 26, 2026
·Updated
Affected Software
1 affected component
Gpac GPAC (MP4Box)<fix commit
Frequently Asked Questions
1
What is CVE-2025-60474?
CVE-2025-60474 is a heap-based buffer overflow vulnerability found in GPAC/MP4Box that can be triggered via the gf_media_import function on crafted MPEG-2 TS files.
2
What is the severity of CVE-2025-60474?
The severity of CVE-2025-60474 is rated as medium with a CVSS 3.1 score of 4.3.
3
How do I fix CVE-2025-60474?
To fix CVE-2025-60474, update to a version of GPAC/MP4Box that includes the fix commit addressing this vulnerability.
4
What type of vulnerability is CVE-2025-60474 classified as?
CVE-2025-60474 is classified as CWE-122, which refers to heap-based buffer overflow vulnerabilities.
5
Which versions of GPAC are affected by CVE-2025-60474?
Versions of GPAC/MP4Box prior to the fix commit are affected by CVE-2025-60474.