CVE-2018-13846: Critical severity bento4 vulnerability
Published Jul 10, 2018
·Updated
An issue has been found in Bento4 1.5.1-624. AP4Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-2018-14532.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-624
Event History
Jul 10, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13846?
CVE-2018-13846 is classified as a high-severity vulnerability due to potential exploitation that could lead to sensitive data exposure.
2
How do I fix CVE-2018-13846?
To mitigate CVE-2018-13846, upgrade Bento4 to version 1.5.1-625 or later where the issue has been patched.
3
What type of vulnerability is CVE-2018-13846?
CVE-2018-13846 is a heap-based buffer over-read vulnerability that occurs during processing in specific MP4 formats.
4
Which versions of Bento4 are affected by CVE-2018-13846?
CVE-2018-13846 affects Bento4 version 1.5.1-624 specifically.
5
Is there a workaround for CVE-2018-13846 if I can't update?
There are no recommended workarounds for CVE-2018-13846, so updating to a fixed version is the best course of action.