First published: Sun Feb 10 2019(Updated: )
A heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remote attackers could leverage this vulnerability to cause an exception via crafted mp4 input, which leads to a denial of service.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-627 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7699 is classified as a denial of service vulnerability due to potential heap-based buffer over-read.
To mitigate CVE-2019-7699, update to a version of Bento4 later than 1.5.1-627 that addresses this vulnerability.
CVE-2019-7699 is a heap-based buffer over-read vulnerability in the Bento4 software.
Yes, CVE-2019-7699 can be exploited remotely using crafted mp4 files.
CVE-2019-7699 specifically affects Bento4 version 1.5.1-627.