CVE-2025-70304

7.5

GPAC · GPAC

A buffer overflow in the vobsub_get_subpic_duration function of GPAC version 2.4.0 permits unauthenticated attackers to trigger a Denial of Service via a crafted packet.

Executive summary

A buffer overflow vulnerability in GPAC version 2.4.0 poses a significant risk of service disruption, as unauthenticated attackers can remotely trigger a crash.

Vulnerability

This is a buffer overflow vulnerability located in the vobsub_get_subpic_duration function. The flaw is remotely exploitable by an unauthenticated attacker who can send a crafted packet to cause a Denial of Service.

Business impact

The primary impact of this vulnerability is the potential for unplanned system downtime and loss of service availability. With a CVSS score of 7.5, the vulnerability is classified as High, reflecting the ease of exploitation over a network without requiring authentication. Organizations relying on this software for media processing may face service interruptions that impact operational continuity.

Remediation

Immediate Action: Monitor official GPAC project channels for the release of a security patch and apply it immediately upon availability.

Proactive Monitoring: Review network traffic and server logs for anomalous packet structures or repeated service crashes that may indicate exploitation attempts.

Compensating Controls: Deploy network intrusion detection systems to identify and block malformed packets targeting the vobsub processing functionality.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the technical write-up provided in the vulnerability references.

Analyst recommendation

Given the High severity rating and the existence of a public proof-of-concept, this vulnerability warrants immediate attention. Administrators should prioritize identifying instances of GPAC version 2.4.0 within their environment and prepare to patch as soon as the vendor provides a remediation update to prevent potential service instability.

More GPAC CVEs

Sources