A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.
| Vendor | Product | Versions |
|---|---|---|
| gpac project | mp4box | n/a |
Updated description with more technical detail, added CWE-416, and changed CVSS score from 6.1 to 4.3.
Updated vendor and product information, marked severity as CRITICAL, and noted that an exploit is available and the vulnerability is actively exploited.
Initial creation