CVE-2019-15047: High severity bento4 vulnerability
Published Aug 14, 2019
·Updated
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4BitReader::SkipBits at Core/Ap4Utils.cpp.
Affected Software
1 affected component
Axiosys Bento4=1.5.1.0
Event History
Aug 14, 2019
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15047?
CVE-2019-15047 has been classified with a high severity due to the potential for a heap-based buffer over-read.
2
How do I fix CVE-2019-15047?
To fix CVE-2019-15047, you should update Bento4 to a version that is not affected, ideally a version higher than 1.5.1.0.
3
What is the impact of CVE-2019-15047 on my system?
CVE-2019-15047 could lead to information disclosure or potential remote code execution due to the heap-based buffer over-read.
4
Which software is affected by CVE-2019-15047?
CVE-2019-15047 specifically affects Bento4 version 1.5.1.0.
5
Where can I find more information about CVE-2019-15047?
You can find additional details on CVE-2019-15047 by checking the issue tracking pages of Bento4 repositories.