A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.
| Vendor | Product | Versions |
|---|---|---|
| gpac project | mp4box | n/a |
Updated description with more technical detail, changed CVSS to 4.3, added CWE-825, and specified affected versions as prior to fix commit.
Updated vendor to GPAC Project, product to MP4Box, affected versions to 26.1.x, severity to CRITICAL, and marked the exploit as available and actively exploited.
Initial creation