PT-2023-22324 · Mp4V2 · Mp4V2

Z1R00

·

Published

2023-04-14

·

Updated

2023-04-19

·

CVE-2023-29584

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mp4v2 version 2.0.0
Description The issue is a heap buffer overflow that occurs via the MP4GetVideoProfileLevel function at /src/mp4.cpp. This function is part of the mp4v2 library, which is used for handling MP4 files. The heap buffer overflow can potentially lead to arbitrary code execution or crashes.
Recommendations For mp4v2 version 2.0.0, consider disabling the MP4GetVideoProfileLevel function until a patch is available to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-29584

Affected Products

Mp4V2