CVE-2017-14260: Buffer Overflow
Published Sep 11, 2017
·Updated
In the SDK in Bento4 1.5.0-616, the AP4StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.
Affected Software
1 affected component
Axiosys Bento4=1.5.0-616
Event History
Sep 11, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14260?
CVE-2017-14260 is classified as a critical vulnerability due to its potential to execute arbitrary code.
2
How do I fix CVE-2017-14260?
To mitigate CVE-2017-14260, update to a patched version of Bento4 beyond 1.5.0-616.
3
What systems are affected by CVE-2017-14260?
CVE-2017-14260 specifically affects Bento4 version 1.5.0-616.
4
What type of vulnerability is CVE-2017-14260?
CVE-2017-14260 is a Write Memory Access Violation vulnerability.
5
Can CVE-2017-14260 be exploited remotely?
Yes, CVE-2017-14260 can potentially be exploited remotely by opening a crafted .MP4 file.