CVE-2018-14589: High severity bento4 vulnerability
Published Jul 24, 2018
·Updated
An issue has been discovered in Bento4 1.5.1-624. AP4Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-624
Event History
Jul 24, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14589?
CVE-2018-14589 is classified as a moderate severity vulnerability due to its potential for a heap-based buffer over-read.
2
How do I fix CVE-2018-14589?
To mitigate CVE-2018-14589, you should upgrade to a later version of Bento4 that addresses this vulnerability.
3
Which versions of Bento4 are affected by CVE-2018-14589?
CVE-2018-14589 affects Bento4 version 1.5.1-624.
4
What is the nature of the vulnerability in CVE-2018-14589?
CVE-2018-14589 involves a heap-based buffer over-read in the AP4_Mp4AudioDsiParser::ReadBits function.
5
Is CVE-2018-14589 exploitable remotely?
CVE-2018-14589 may be exploitable remotely if the vulnerable software processes untrusted inputs.