First published: Thu Sep 21 2017(Updated: )
AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL pointer dereference, segmentation fault, and application crash in AP4_Atom::SetType in Core/Ap4Atom.h.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.0-617 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14638 has a medium severity rating due to the potential for application crashes.
To fix CVE-2017-14638, update Bento4 to a version higher than 1.5.0-617 that includes the necessary NULL checks.
The impact of CVE-2017-14638 includes a NULL pointer dereference that can lead to segmentation faults and crashes of the affected application.
Bento4 version 1.5.0-617 is affected by CVE-2017-14638.
CVE-2017-14638 may be exploitable remotely if an attacker can send crafted inputs to the application using the affected version of Bento4.