CVE-2017-14643: Medium severity centos libgcc vulnerability
Published Sep 21, 2017
·Updated
The AP4HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over-read and application crash in AP4BytesToUInt32BE in Core/Ap4Utils.h.
Affected Software
1 affected component
Bento4 Bento4=1.5.0-617
Remediation
Event History
Sep 21, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14643?
CVE-2017-14643 is classified as a high severity vulnerability due to its potential for causing application crashes.
2
How do I fix CVE-2017-14643?
To fix CVE-2017-14643, upgrade to a later version of Bento4 that addresses the heap-based buffer over-read.
3
What impact does CVE-2017-14643 have on Bento4?
CVE-2017-14643 can lead to heap-based buffer over-reads and may cause application crashes.
4
Which version of Bento4 is affected by CVE-2017-14643?
CVE-2017-14643 affects Bento4 version 1.5.0-617.
5
Can CVE-2017-14643 be exploited remotely?
CVE-2017-14643 does not appear to have documented remote exploitability but can lead to a crash if targeted.