PT-2018-15360 · Axiomatic Systems · Bento4

Pikaqqq

·

Published

2018-12-23

·

Updated

2019-10-03

·

CVE-2018-20409

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bento4 version 1.5.1-627
Description A heap-based buffer over-read issue was discovered in the AP4 AvccAtom::Create function in Core/Ap4AvccAtom.cpp. This issue is demonstrated by the mp42hls tool.
Recommendations For Bento4 version 1.5.1-627, consider restricting access to the AP4 AvccAtom::Create function in Core/Ap4AvccAtom.cpp until a patch is available. As a temporary workaround, avoid using the mp42hls tool with this version of Bento4.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20409

Affected Products

Bento4