First published: Fri Jan 11 2019(Updated: )
An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp when called from the AP4_EsdsAtom class in Core/Ap4EsdsAtom.cpp, as demonstrated by mp42aac.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-627 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6132 is classified as a medium severity vulnerability due to its memory leak issue.
To fix CVE-2019-6132, it is recommended to update Bento4 to a version later than 1.5.1-627.
CVE-2019-6132 affects Bento4 version 1.5.1-627 where memory management is handled poorly.
The potential consequences of CVE-2019-6132 include performance degradation due to excessive memory use.
The AP4_DescriptorFactory::CreateDescriptorFromStream function in the AP4_EsdsAtom class is involved in CVE-2019-6132.