First published: Wed Dec 26 2018(Updated: )
An issue was discovered in Bento4 1.5.1-627. There is an attempt at excessive memory allocation in the AP4_DataBuffer class when called from AP4_HvccAtom::Create in Core/Ap4HvccAtom.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-627 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20502 is rated as a high severity vulnerability due to excessive memory allocation risks.
CVE-2018-20502 can lead to potential denial of service conditions due to excessive memory usage.
CVE-2018-20502 specifically affects Bento4 version 1.5.1-627.
To fix CVE-2018-20502, users should upgrade to a patched version of Bento4 that resolves the excessive memory allocation issue.
CVE-2018-20502 is caused by improper handling of data in the AP4_DataBuffer class within the Bento4 library.