CVE-2018-14544: Medium severity bento4 vulnerability
There exists one invalid memory read bug in AP4SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14544?
CVE-2018-14544 has been classified as a vulnerability that can lead to denial-of-service, indicating a moderate severity.
How do I fix CVE-2018-14544?
To fix CVE-2018-14544, it is recommended to upgrade to a later version of Bento4 that addresses this invalid memory read issue.
What does CVE-2018-14544 affect?
CVE-2018-14544 affects Bento4 version 1.5.1-624 and can be exploited via crafted mp4 files.
Can CVE-2018-14544 be exploited remotely?
Yes, CVE-2018-14544 can potentially be exploited remotely if an attacker sends a specially crafted mp4 file to the vulnerable Bento4 application.
Is there a workaround for CVE-2018-14544?
Currently, the best workaround for CVE-2018-14544 is to avoid processing untrusted mp4 files until the software is updated.