CVE-2018-14532: Critical severity bento4 vulnerability
Published Jul 23, 2018
·Updated
An issue was discovered in Bento4 1.5.1-624. There is a heap-based buffer over-read in AP4Mpeg2TsVideoSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp after a call from Mp42Hls.cpp, a related issue to CVE-2018-13846.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-624
Event History
Jul 23, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14532?
CVE-2018-14532 is considered a medium severity vulnerability due to its potential for exploitation through heap-based buffer over-read.
2
How do I fix CVE-2018-14532?
To fix CVE-2018-14532, upgrade Bento4 to version 1.5.1-625 or later, where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2018-14532?
CVE-2018-14532 is a heap-based buffer over-read vulnerability affecting the Bento4 media processing library.
4
Which software versions are affected by CVE-2018-14532?
CVE-2018-14532 affects Bento4 version 1.5.1-624 specifically.
5
Is CVE-2018-14532 related to any other vulnerabilities?
Yes, CVE-2018-14532 is related to CVE-2018-13846, both involving similar issues in the Bento4 library.