Security Advisory

CVE-2026-1417

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-26 03:32:07
Last updated 2026-02-23 08:56:11
Assigner VulDB
CVSS score 4.8
State PUBLISHED

Description

A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dump_isom_rtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: f96bd57c3ccdcde4335a0be28cd3e8fe296993de. Applying a patch is the recommended action to fix this issue.