First published: Tue Jul 10 2018(Updated: )
An issue has been found in Bento4 1.5.1-624. AP4_Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp has a heap-based buffer over-read after a call from Mp42Ts.cpp, a related issue to CVE-2018-14532.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-624 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13846 is classified as a high-severity vulnerability due to potential exploitation that could lead to sensitive data exposure.
To mitigate CVE-2018-13846, upgrade Bento4 to version 1.5.1-625 or later where the issue has been patched.
CVE-2018-13846 is a heap-based buffer over-read vulnerability that occurs during processing in specific MP4 formats.
CVE-2018-13846 affects Bento4 version 1.5.1-624 specifically.
There are no recommended workarounds for CVE-2018-13846, so updating to a fixed version is the best course of action.