PT-2022-23531 · Axiomatic+1 · Axiomatic Bento4+1

Burymyname

·

Published

2022-10-26

·

Updated

2024-04-08

·

CVE-2022-3666

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axiomatic Bento4 (affected versions not specified)
Description A critical issue has been found in Axiomatic Bento4, affecting the AP4 LinearReader::Advance function of the Ap4LinearReader.cpp file in the mp42ts component. This issue leads to use after free and can be exploited remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-6114
CVE-2022-3666

Affected Products

Alt Linux
Axiomatic Bento4