A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
| Vendor | Product | Versions |
|---|---|---|
| gpac project | mp4box | n/a |
Updated description with more technical detail, changed severity to MEDIUM, and updated CVSS score to 4.3 with new CWE-122.
Updated vendor to GPAC, product to MP4Box, affected versions to 26.1.x, severity to CRITICAL, and marked the vulnerability as actively exploited with an exploit available.
Initial creation