CVE-2025-7797 | GPAC up to 2.4 dash_client.c gf_dash_download_init_segment base_init_url null pointer dereference (EUVD-2025-21911 / Nessus ID 248410)
A vulnerability classified as problematic has been found in GPAC up to 2.4. The affected element is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. This manipulation of the argument base_init_url causes null pointer dereference.
This vulnerability is handled as CVE-2025-7797. The attack can be initiated remotely. Additionally, an exploit exists.
Applying a patch is the recommended action to fix this issue.