First published: Mon Jul 23 2018(Updated: )
There exists one invalid memory read bug in AP4_SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-624 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14544 has been classified as a vulnerability that can lead to denial-of-service, indicating a moderate severity.
To fix CVE-2018-14544, it is recommended to upgrade to a later version of Bento4 that addresses this invalid memory read issue.
CVE-2018-14544 affects Bento4 version 1.5.1-624 and can be exploited via crafted mp4 files.
Yes, CVE-2018-14544 can potentially be exploited remotely if an attacker sends a specially crafted mp4 file to the vulnerable Bento4 application.
Currently, the best workaround for CVE-2018-14544 is to avoid processing untrusted mp4 files until the software is updated.