CVE-2018-20502: Medium severity bento4 vulnerability
Published Dec 26, 2018
·Updated
An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4DataBuffer class when called from AP4HvccAtom::Create in Core/Ap4HvccAtom.cpp.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-627
Event History
Dec 26, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20502?
CVE-2018-20502 is rated as a high severity vulnerability due to excessive memory allocation risks.
2
How does CVE-2018-20502 affect users of Bento4?
CVE-2018-20502 can lead to potential denial of service conditions due to excessive memory usage.
3
What versions of Bento4 are impacted by CVE-2018-20502?
CVE-2018-20502 specifically affects Bento4 version 1.5.1-627.
4
How do I fix CVE-2018-20502?
To fix CVE-2018-20502, users should upgrade to a patched version of Bento4 that resolves the excessive memory allocation issue.
5
What is the cause of CVE-2018-20502?
CVE-2018-20502 is caused by improper handling of data in the AP4_DataBuffer class within the Bento4 library.