Axiomatic Systems · Bento4 · CVE-2019-6966
**Name of the Vulnerable Software and Affected Versions**
Bento4 version 1.5.1-628
**Description**
An issue was discovered related to excessive memory allocation in the AP4 ElstAtom class. This issue is associated with the AP4 Array<AP4 ElstEntry>::EnsureCapacity function in Core/Ap4Array.h, as demonstrated by mp42hls.
**Recommendations**
For Bento4 version 1.5.1-628, consider restricting the use of the AP4 ElstAtom class until a patch is available. As a temporary workaround, avoid using the AP4 Array<AP4 ElstEntry>::EnsureCapacity function to minimize the risk of exploitation.