PT-2026-3082 · Gpac · Gpac

CVE-2025-70299

·

Published

2025-01-01

·

Updated

2026-01-17

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GPAC version 2.4.0
Description A heap overflow exists in the avi parse input file() function. This issue can be triggered by processing a specially crafted AVI file, potentially leading to a Denial of Service (DoS).
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to or avoiding the processing of untrusted AVI files.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00596
CVE-2025-70299

Affected Products

Gpac