CVE-2019-6966: Medium severity bento4 vulnerability
An issue was discovered in Bento4 1.5.1-628. The AP4ElstAtom class in Core/Ap4ElstAtom.cpp has an attempted excessive memory allocation related to AP4Array<AP4ElstEntry>::EnsureCapacity in Core/Ap4Array.h, as demonstrated by mp42hls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6966?
CVE-2019-6966 is classified as a moderate severity vulnerability due to potential denial of service resulting from excessive memory allocation.
How do I fix CVE-2019-6966?
To fix CVE-2019-6966, update Bento4 to version 1.5.1-629 or later, which addresses the excessive memory allocation issue.
What applications are affected by CVE-2019-6966?
CVE-2019-6966 affects Bento4 version 1.5.1-628 specifically.
What is the impact of CVE-2019-6966?
The impact of CVE-2019-6966 can lead to application crashes or denial of service due to memory allocation failures.
How was CVE-2019-6966 discovered?
CVE-2019-6966 was discovered through code analysis related to the AP4_ElstAtom class in Bento4.