PT-2022-25384 · Bento4+1 · Bento4+1

17Ssdp

·

Published

2022-09-14

·

Updated

2024-04-08

·

CVE-2022-40438

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bento4 version 1.6.0-639
Description A buffer overflow issue exists in the AP4 MemoryByteStream::WritePartial function in mp42aac, which can be exploited by attackers to cause a denial of service. This can be achieved by providing a crafted file.
Recommendations For Bento4 version 1.6.0-639, consider disabling the AP4 MemoryByteStream::WritePartial function as a temporary workaround until a patch is available. Restrict access to mp42aac to minimize the risk of exploitation. Avoid using crafted files that may trigger the buffer overflow issue until the problem is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-6114
CVE-2022-40438

Affected Products

Alt Linux
Bento4