Vulnerability Details CVE-2025-60468
GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580): function gf_filter_pid_inst_swap_delete_task() improperly accesses freed objects during PID instance swap/delete cleanup, leading to heap use-after-free. The attack vector is: Local (AV:L): a local, authenticated user who processes a specially crafted MPEG-2 TS/MP4 file with MP4Box can trigger the bug during filter teardown (PID instance swap/delete), causing a crash. ¶¶ In GPAC s MP4Box, gf_filter_pid_inst_swap_delete_task() in filter_core/filter_pid.c may dereference objects after they have been freed when cleaning up PID instances after a swap/delete operation. Crafted inputs (e.g., malformed MPEG-2 TS) can trigger a heap use-after-free and crash; exploitation may be possible.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.9%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2025-60468
-
-
cpe:2.3:a:gpac:gpac:0.5.2
-
cpe:2.3:a:gpac:gpac:0.6.0
-
cpe:2.3:a:gpac:gpac:0.6.1
-
cpe:2.3:a:gpac:gpac:0.7.0
-
cpe:2.3:a:gpac:gpac:0.7.1
-
cpe:2.3:a:gpac:gpac:0.8.0
-
cpe:2.3:a:gpac:gpac:0.9.0
-
Gpac
»
Gpac
»
Version: 0.9.0-development-20191109
cpe:2.3:a:gpac:gpac:0.9.0-development-20191109
-
-
cpe:2.3:a:gpac:gpac:1.0.1
-
cpe:2.3:a:gpac:gpac:1.1.0
-
Gpac
»
Gpac
»
Version: 1.1.0-dev-rev1663-g881c6a94a-master
cpe:2.3:a:gpac:gpac:1.1.0-dev-rev1663-g881c6a94a-master
-
Gpac
»
Gpac
»
Version: 1.1.0-dev-rev1727-g8be34973d-master
cpe:2.3:a:gpac:gpac:1.1.0-dev-rev1727-g8be34973d-master
-
Gpac
»
Gpac
»
Version: 1.1.0-dev-rev1759-geb2d1e6dd
cpe:2.3:a:gpac:gpac:1.1.0-dev-rev1759-geb2d1e6dd
-
-
cpe:2.3:a:gpac:gpac:2.0.0
-
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev368-gfd054169b-master
cpe:2.3:a:gpac:gpac:2.1-dev-rev368-gfd054169b-master
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev428-gcb8ae46c8-master
cpe:2.3:a:gpac:gpac:2.1-dev-rev428-gcb8ae46c8-master
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev478-g696e6f868-master
cpe:2.3:a:gpac:gpac:2.1-dev-rev478-g696e6f868-master
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev490-g68064e101-master
cpe:2.3:a:gpac:gpac:2.1-dev-rev490-g68064e101-master
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev505-gb9577e6ad-master
cpe:2.3:a:gpac:gpac:2.1-dev-rev505-gb9577e6ad-master
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev574-g9d5bb184b
cpe:2.3:a:gpac:gpac:2.1-dev-rev574-g9d5bb184b
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev593-g007bf61a0
cpe:2.3:a:gpac:gpac:2.1-dev-rev593-g007bf61a0
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev617-g85ce76efd
cpe:2.3:a:gpac:gpac:2.1-dev-rev617-g85ce76efd
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev644-g5c4df2a67
cpe:2.3:a:gpac:gpac:2.1-dev-rev644-g5c4df2a67
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev649-ga8f438d20
cpe:2.3:a:gpac:gpac:2.1-dev-rev649-ga8f438d20
-
Gpac
»
Gpac
»
Version: 2.1-dev-rev87-g053aae8-master
cpe:2.3:a:gpac:gpac:2.1-dev-rev87-g053aae8-master
-
Gpac
»
Gpac
»
Version: 2.2-rev0-gab012bbfb-master
cpe:2.3:a:gpac:gpac:2.2-rev0-gab012bbfb-master
-
cpe:2.3:a:gpac:gpac:2.2.0
-
cpe:2.3:a:gpac:gpac:2.2.1
-
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev1-g4669ba229-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev1-g4669ba229-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev35-gbbca86917-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev35-gbbca86917-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev381-g817a848f6-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev381-g817a848f6-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev40-g3602a5ded
cpe:2.3:a:gpac:gpac:2.3-dev-rev40-g3602a5ded
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev566-g50c2ab06f-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev566-g50c2ab06f-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev573-g201320819-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev573-g201320819-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev602-ged8424300-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev602-ged8424300-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev605-gfc9e29089-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev605-gfc9e29089-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev617-g671976fcc-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev617-g671976fcc-master
-
Gpac
»
Gpac
»
Version: 2.3-dev-rev636-gfbd7e13aa-master
cpe:2.3:a:gpac:gpac:2.3-dev-rev636-gfbd7e13aa-master
-
cpe:2.3:a:gpac:gpac:2.3.0
-
cpe:2.3:a:gpac:gpac:2.3.0-dev