First published: Fri Jul 20 2018(Updated: )
In Bento4 v1.5.1-624, AP4_File::ParseStream in Ap4File.cpp allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-624 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14445 has a severity rating of medium due to its potential to cause denial of service.
To fix CVE-2018-14445, upgrade to a newer version of Bento4 that addresses this vulnerability.
CVE-2018-14445 is caused by a vulnerability in the AP4_File::ParseStream function, allowing remote attackers to trigger an infinite loop using a crafted MP4 file.
Users of Bento4 version 1.5.1-624 are specifically affected by CVE-2018-14445.
CVE-2018-14445 was disclosed in 2018.