PT-2018-15360 · Axiomatic Systems · Bento4
Pikaqqq
·
Published
2018-12-23
·
Updated
2019-10-03
·
CVE-2018-20409
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Bento4 version 1.5.1-627
Description
A heap-based buffer over-read issue was discovered in the AP4 AvccAtom::Create function in Core/Ap4AvccAtom.cpp. This issue is demonstrated by the mp42hls tool.
Recommendations
For Bento4 version 1.5.1-627, consider restricting access to the AP4 AvccAtom::Create function in Core/Ap4AvccAtom.cpp until a patch is available. As a temporary workaround, avoid using the mp42hls tool with this version of Bento4.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bento4