CVE-2019-17530: High severity bento4 vulnerability
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4PrintInspector::AddField in Core/Ap4Atom.cpp when called from AP4CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp, when called from AP4Atom::Inspect in Core/Ap4Atom.cpp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17530?
CVE-2019-17530 is considered to be a medium severity vulnerability due to the potential for a heap-based buffer over-read.
How do I fix CVE-2019-17530?
To fix CVE-2019-17530, users should upgrade to a patched version of Bento4 if available, or apply relevant security patches provided by the vendor.
What type of vulnerability is CVE-2019-17530?
CVE-2019-17530 is classified as a heap-based buffer over-read vulnerability.
Which versions of Bento4 are affected by CVE-2019-17530?
CVE-2019-17530 specifically affects Bento4 version 1.5.1.0.
Can CVE-2019-17530 be exploited remotely?
Yes, CVE-2019-17530 may be exploited by attackers through maliciously crafted input that can trigger the buffer over-read.