PT-2026-29402 · Axiomatic · Bento4
Breakingbad
·
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2026-5235
CVSS v3.1
5.3
Medium
| AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4 BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation causes heap-based buffer overflow. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bento4