CVE-2017-14638: Null Pointer Dereference
AP4AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL pointer dereference, segmentation fault, and application crash in AP4Atom::SetType in Core/Ap4Atom.h.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14638?
CVE-2017-14638 has a medium severity rating due to the potential for application crashes.
How do I fix CVE-2017-14638?
To fix CVE-2017-14638, update Bento4 to a version higher than 1.5.0-617 that includes the necessary NULL checks.
What is the impact of CVE-2017-14638?
The impact of CVE-2017-14638 includes a NULL pointer dereference that can lead to segmentation faults and crashes of the affected application.
Which version of Bento4 is affected by CVE-2017-14638?
Bento4 version 1.5.0-617 is affected by CVE-2017-14638.
Is CVE-2017-14638 exploitable remotely?
CVE-2017-14638 may be exploitable remotely if an attacker can send crafted inputs to the application using the affected version of Bento4.