A segmentation violation in the gfisomapplesettagex function (/isomedia/isomwrite.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/60xxx/CVE-2025-60485.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60485.json"
[
{
"target": {
"file": "src/filters/dasher.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457",
"id": "CVE-2025-60485-00c0f560",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"52111653915113089630664413940784894901",
"248864185704256495598778090078494880216",
"339159385276364089624143265040559938533",
"209039521461276481942614754801473598435"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "dasher_insert_timeline_entry",
"file": "src/filters/dasher.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457",
"id": "CVE-2025-60485-0a2d024d",
"signature_version": "v1",
"digest": {
"length": 5713.0,
"function_hash": "129380554801158614920303728030288125792"
},
"signature_type": "Function"
},
{
"target": {
"file": "src/isomedia/isom_write.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457",
"id": "CVE-2025-60485-31f81de3",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"222294176078787918371677437871969916108",
"92197578121446956091102328783020570187",
"82330928626424416097322476715910757758",
"98765442299974951605535283230041265292",
"196851035798921164669545600734954041329",
"115862902744282703220614625257910315261"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "src/filters/isoffin_load.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457",
"id": "CVE-2025-60485-5910da8b",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"89151889467647335910848669509305146863",
"236732265184660035366467935863000898408",
"42633452720109036350159864582631581054",
"339872732369043109995943122172718635502"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "isor_setup_channel",
"file": "src/filters/isoffin_load.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457",
"id": "CVE-2025-60485-605a44cf",
"signature_version": "v1",
"digest": {
"length": 17204.0,
"function_hash": "192296102003013210338681233211692623125"
},
"signature_type": "Function"
},
{
"target": {
"function": "gf_isom_apple_set_tag_ex",
"file": "src/isomedia/isom_write.c"
},
"deprecated": false,
"source": "https://github.com/gpac/gpac/commit/4860a1a6f128ccc9ae37b4b738d22029f9672457",
"id": "CVE-2025-60485-ac09f8df",
"signature_version": "v1",
"digest": {
"length": 7028.0,
"function_hash": "176775137166059604832151108012073885291"
},
"signature_type": "Function"
}
]
"2026-08-12T15:14:16Z"