PT-2022-25500 · Bento4+1 · Bento4+1

Han Zheng

+1

·

Published

2022-09-15

·

Updated

2024-04-08

·

CVE-2022-40738

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bento4 versions 1.6.0-639 and earlier
Description An issue was discovered that leads to a NULL pointer dereference in AP4 DescriptorListWriter::Action in Core/Ap4Descriptor.h. This issue is called from AP4 EsDescriptor::WriteFields and AP4 Expandable::Write.
Recommendations For Bento4 versions 1.6.0-639 and earlier, consider disabling the AP4 DescriptorListWriter::Action function as a temporary workaround until a patch is available. Restrict access to the Core/Ap4Descriptor.h module to minimize the risk of exploitation. Avoid using the affected functions AP4 EsDescriptor::WriteFields and AP4 Expandable::Write until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2024-6114
CVE-2022-40738

Affected Products

Alt Linux
Bento4