CVE-2025-70307

7.5

GPAC · GPAC

A stack overflow vulnerability in the dump_ttxt_sample function of GPAC version 2.4.0 allows unauthenticated remote attackers to trigger a denial of service via a crafted packet.

Executive summary

A critical stack overflow vulnerability in GPAC version 2.4.0 allows unauthenticated attackers to cause a denial of service, necessitating immediate monitoring and patching.

Vulnerability

This is a stack overflow vulnerability occurring within the dump_ttxt_sample function. An unauthenticated attacker can trigger this flaw by sending a specially crafted packet to the application.

Business impact

Successful exploitation of this vulnerability results in a denial of service, which can cause significant system instability or downtime for services relying on the GPAC library. With a CVSS score of 7.5, this is considered a high-severity issue because it allows remote, unauthenticated attackers to disrupt availability without requiring prior system access or user interaction.

Remediation

Immediate Action: Since a specific patch is not yet confirmed, prioritize isolating systems running GPAC 2.4.0 and restrict network access to the affected services.

Proactive Monitoring: Monitor system logs for unexpected crashes or service restarts associated with the GPAC library, as these may indicate attempted exploitation.

Compensating Controls: Implement network-level filtering to block malformed or suspicious packets directed at services using GPAC, which can serve as a temporary mitigation against the exploitation of this stack overflow.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up referenced in the CVE record.

Analyst recommendation

Given the availability of a public proof-of-concept and the ease of remote exploitation, organizations should immediately identify all instances of GPAC 2.4.0 within their environment. While waiting for an official vendor patch, restrict access to the affected software and apply network filtering to mitigate the risk of a denial of service attack.

More GPAC CVEs

Sources