CVE-2019-7698: Medium severity bento4 vulnerability
Published Feb 10, 2019
·Updated
An issue was discovered in AP4Array<AP4CttsTableEntry>::EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by mp42hls, a related issue to CVE-2018-20095.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-627
Event History
Feb 10, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-7698?
The severity of CVE-2019-7698 is classified as high due to the potential for excessive memory allocation leading to denial of service.
2
How do I fix CVE-2019-7698?
To fix CVE-2019-7698, upgrade to a patched version of Bento4 that addresses this vulnerability.
3
What software is affected by CVE-2019-7698?
CVE-2019-7698 affects the Bento4 version 1.5.1-627.
4
What type of attack does CVE-2019-7698 demonstrate?
CVE-2019-7698 demonstrates an attack using crafted MP4 input to trigger memory issues.
5
What does CVE-2019-7698 exploit in Bento4?
CVE-2019-7698 exploits the AP4_Array EnsureCapacity function in Bento4 leading to memory allocation vulnerabilities.