CVE-2019-17529: High severity bento4 vulnerability
Published Oct 12, 2019
·Updated
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp when called from AP4Atom::Inspect in Core/Ap4Atom.cpp.
Affected Software
1 affected component
Axiosys Bento4=1.5.1.0
Event History
Oct 12, 2019
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17529?
CVE-2019-17529 is classified as a high severity vulnerability due to its potential for a heap-based buffer over-read.
2
How do I fix CVE-2019-17529?
To address CVE-2019-17529, upgrade Bento4 to a version that is not vulnerable, specifically a version newer than 1.5.1.0.
3
What kind of vulnerability is CVE-2019-17529?
CVE-2019-17529 is a heap-based buffer over-read vulnerability affecting Bento4.
4
Which software versions are affected by CVE-2019-17529?
CVE-2019-17529 affects Bento4 version 1.5.1.0.
5
Where can I find more information about CVE-2019-17529?
Additional details about CVE-2019-17529 can be found in the security advisories and GitHub issue discussions related to Bento4.