Axiomatic Systems · Bento4 · CVE-2018-20407
**Name of the Vulnerable Software and Affected Versions**
Bento4 version 1.5.1-627
**Description**
A memory leak issue was found in the `AP4 DescriptorFactory::CreateDescriptorFromStream` function, located in `Core/Ap4DescriptorFactory.cpp`. This issue is demonstrated by the `mp42hls` tool.
**Recommendations**
For Bento4 version 1.5.1-627, consider applying a patch or fix to address the memory leak in the `AP4 DescriptorFactory::CreateDescriptorFromStream` function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.