CVE-2025-70304
7.5GPAC · GPAC
A buffer overflow in the vobsub_get_subpic_duration function of GPAC version 2.4.0 permits unauthenticated attackers to trigger a Denial of Service via a crafted packet.
Executive summary
A buffer overflow vulnerability in GPAC version 2.4.0 poses a significant risk of service disruption, as unauthenticated attackers can remotely trigger a crash.
Vulnerability
This is a buffer overflow vulnerability located in the vobsub_get_subpic_duration function. The flaw is remotely exploitable by an unauthenticated attacker who can send a crafted packet to cause a Denial of Service.
Business impact
The primary impact of this vulnerability is the potential for unplanned system downtime and loss of service availability. With a CVSS score of 7.5, the vulnerability is classified as High, reflecting the ease of exploitation over a network without requiring authentication. Organizations relying on this software for media processing may face service interruptions that impact operational continuity.
Remediation
Immediate Action: Monitor official GPAC project channels for the release of a security patch and apply it immediately upon availability.
Proactive Monitoring: Review network traffic and server logs for anomalous packet structures or repeated service crashes that may indicate exploitation attempts.
Compensating Controls: Deploy network intrusion detection systems to identify and block malformed packets targeting the vobsub processing functionality.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical write-up provided in the vulnerability references.
Analyst recommendation
Given the High severity rating and the existence of a public proof-of-concept, this vulnerability warrants immediate attention. Administrators should prioritize identifying instances of GPAC version 2.4.0 within their environment and prepare to patch as soon as the vendor provides a remediation update to prevent potential service instability.