CVE-2018-14587: High severity bento4 vulnerability
Published Jul 24, 2018
·Updated
An issue has been discovered in Bento4 1.5.1-624. AP4MemoryByteStream::WritePartial in Core/Ap4ByteStream.cpp has a buffer over-read.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-624
Event History
Jul 24, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14587?
CVE-2018-14587 is classified as a moderate severity vulnerability due to its potential to lead to unauthorized information disclosure.
2
How do I fix CVE-2018-14587?
To address CVE-2018-14587, upgrade Bento4 to version 1.5.1-626 or later, which contains the necessary patch.
3
What are the impacts of CVE-2018-14587?
CVE-2018-14587 may allow an attacker to exploit a buffer over-read to access sensitive information.
4
Which versions of Bento4 are affected by CVE-2018-14587?
CVE-2018-14587 affects Bento4 version 1.5.1-624 and earlier.
5
Is CVE-2018-14587 a known issue in the community?
Yes, CVE-2018-14587 has been acknowledged by the community and there is a discussion about it on GitHub.