A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
| Vendor | Product | Versions |
|---|---|---|
| gpac project | mp4box | n/a |
Updated description with more technical detail, affected versions, CVSS score to 4.3, and added CWE-476.
Updated vendor to GPAC Project, product to MP4Box, affected versions to 26.1.x, severity to HIGH, and marked exploit as available and actively exploited.
Initial creation