CVE-2018-20407: Medium severity Axiosys Bento4 vulnerability
Published Dec 23, 2018
·Updated
An issue was discovered in Bento4 1.5.1-627. There is a memory leak in AP4DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp, as demonstrated by mp42hls.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-627
Event History
Dec 23, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20407?
CVE-2018-20407 has been classified as a medium severity vulnerability due to its potential impact on memory usage.
2
How do I fix CVE-2018-20407?
To fix CVE-2018-20407, you should upgrade to the latest version of Bento4 that addresses this memory leak issue.
3
What type of vulnerability is CVE-2018-20407?
CVE-2018-20407 is a memory leak vulnerability found in Bento4's descriptor factory functions.
4
Which version of Bento4 is affected by CVE-2018-20407?
CVE-2018-20407 specifically affects Bento4 version 1.5.1-627.
5
What are the potential consequences of CVE-2018-20407?
The potential consequences of CVE-2018-20407 include increased memory usage, which could lead to denial of service in resource-constrained environments.