CVE-2018-20409: Medium severity bento4 vulnerability
Published Dec 23, 2018
·Updated
An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated by mp42hls.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-627
Event History
Dec 23, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20409?
CVE-2018-20409 is classified as a medium severity vulnerability.
2
How does CVE-2018-20409 impact Bento4 users?
CVE-2018-20409 can lead to a heap-based buffer over-read, which may cause information disclosure.
3
How do I fix CVE-2018-20409?
To fix CVE-2018-20409, update to a newer version of Bento4 that addresses the heap-based buffer over-read.
4
What versions of Bento4 are affected by CVE-2018-20409?
Bento4 version 1.5.1-627 is the only version affected by CVE-2018-20409.
5
Is there a workaround for CVE-2018-20409?
There are no documented workarounds for CVE-2018-20409 other than upgrading to a secure version.