CVE-2019-7699: Medium severity bento4 vulnerability
Published Feb 10, 2019
·Updated
A heap-based buffer over-read occurs in AP4BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remote attackers could leverage this vulnerability to cause an exception via crafted mp4 input, which leads to a denial of service.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-627
Event History
Feb 10, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-7699?
CVE-2019-7699 is classified as a denial of service vulnerability due to potential heap-based buffer over-read.
2
How do I fix CVE-2019-7699?
To mitigate CVE-2019-7699, update to a version of Bento4 later than 1.5.1-627 that addresses this vulnerability.
3
What type of vulnerability is CVE-2019-7699?
CVE-2019-7699 is a heap-based buffer over-read vulnerability in the Bento4 software.
4
Can CVE-2019-7699 be exploited remotely?
Yes, CVE-2019-7699 can be exploited remotely using crafted mp4 files.
5
What is impacted by CVE-2019-7699?
CVE-2019-7699 specifically affects Bento4 version 1.5.1-627.