CVE-2018-14445: Medium severity bento4 vulnerability
Published Jul 20, 2018
·Updated
In Bento4 v1.5.1-624, AP4File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-624
Event History
Jul 20, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14445?
CVE-2018-14445 has a severity rating of medium due to its potential to cause denial of service.
2
How do I fix CVE-2018-14445?
To fix CVE-2018-14445, upgrade to a newer version of Bento4 that addresses this vulnerability.
3
What causes CVE-2018-14445?
CVE-2018-14445 is caused by a vulnerability in the AP4_File::ParseStream function, allowing remote attackers to trigger an infinite loop using a crafted MP4 file.
4
Who is affected by CVE-2018-14445?
Users of Bento4 version 1.5.1-624 are specifically affected by CVE-2018-14445.
5
When was CVE-2018-14445 disclosed?
CVE-2018-14445 was disclosed in 2018.