PT-2021-8689 · Bento4 · Bento4

Lvtao-Sec

·

Published

2021-08-25

·

Updated

2021-08-30

·

CVE-2018-10790

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bento4 version 1.5.1.0
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash. This is related to a memory allocation failure in the AP4 CttsAtom class, located in Core/Ap4CttsAtom.cpp. The vulnerability can be demonstrated using mp2aac.
Recommendations For Bento4 version 1.5.1.0, consider updating to a newer version that addresses the memory allocation failure issue in the AP4 CttsAtom class. As a temporary workaround, restrict the use of the AP4 CttsAtom class to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10790

Affected Products

Bento4