CVE-2019-6132: High severity bento4 vulnerability
Published Jan 11, 2019
·Updated
An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4DescriptorFactory::CreateDescriptorFromStream in Core/Ap4DescriptorFactory.cpp when called from the AP4EsdsAtom class in Core/Ap4EsdsAtom.cpp, as demonstrated by mp42aac.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-627
Event History
Jan 11, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6132?
CVE-2019-6132 is classified as a medium severity vulnerability due to its memory leak issue.
2
How do I fix CVE-2019-6132?
To fix CVE-2019-6132, it is recommended to update Bento4 to a version later than 1.5.1-627.
3
What is affected by CVE-2019-6132?
CVE-2019-6132 affects Bento4 version 1.5.1-627 where memory management is handled poorly.
4
What are the potential consequences of CVE-2019-6132?
The potential consequences of CVE-2019-6132 include performance degradation due to excessive memory use.
5
Which class is involved in the CVE-2019-6132 vulnerability?
The AP4_DescriptorFactory::CreateDescriptorFromStream function in the AP4_EsdsAtom class is involved in CVE-2019-6132.