CVE-2018-20095: Medium severity bento4 vulnerability
Published Dec 12, 2018
·Updated
An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by mp42hls.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-627
Event History
Dec 12, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20095?
CVE-2018-20095 has a high severity rating due to excessive memory allocation vulnerabilities.
2
How do I fix CVE-2018-20095?
To fix CVE-2018-20095, upgrade to a patched version of Bento4 that addresses the memory allocation issue.
3
What software versions are affected by CVE-2018-20095?
CVE-2018-20095 affects Bento4 version 1.5.1-627.
4
What type of attack is associated with CVE-2018-20095?
CVE-2018-20095 can be exploited through crafted MP4 input that triggers excessive memory allocation.
5
Is CVE-2018-20095 a critical vulnerability?
CVE-2018-20095 is considered critical as it may lead to denial of service due to resource exhaustion.