CVE-2017-14646: High severity bento4 vulnerability
Published Sep 21, 2017
·Updated
The AP4AvccAtom and AP4HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer over-read and application crash in AP4DataBuffer::SetData in Core/Ap4DataBuffer.cpp.
Affected Software
1 affected component
Axiosys Bento4=1.5.0-617
Remediation
Event History
Sep 21, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14646?
CVE-2017-14646 is considered a high severity vulnerability due to its potential for causing application crashes.
2
How do I fix CVE-2017-14646?
To fix CVE-2017-14646, upgrade Bento4 to version 1.5.0-618 or later, which includes the necessary patches.
3
What types of attacks can exploit CVE-2017-14646?
CVE-2017-14646 can be exploited through specially crafted files that trigger the heap-based buffer over-read.
4
Which software versions are affected by CVE-2017-14646?
CVE-2017-14646 affects Bento4 version 1.5.0-617.
5
What could happen if I don't address CVE-2017-14646?
If not addressed, CVE-2017-14646 may lead to application instability and crashes, affecting user experience and data integrity.