PT-2021-8689 · Bento4 · Bento4
Lvtao-Sec
·
Published
2021-08-25
·
Updated
2021-08-30
·
CVE-2018-10790
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Bento4 version 1.5.1.0
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is related to a memory allocation failure in the AP4 CttsAtom class, located in Core/Ap4CttsAtom.cpp. The vulnerability can be demonstrated using mp2aac.
Recommendations
For Bento4 version 1.5.1.0, consider updating to a newer version that addresses the memory allocation failure issue in the AP4 CttsAtom class. As a temporary workaround, restrict the use of the AP4 CttsAtom class to minimize the risk of exploitation.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bento4