CVE-2019-9544: High severity bento4 vulnerability
An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4CttsTableEntry::AP4CttsTableEntry() located in Core/Ap4Array.h. It can be triggered by sending a crafted file to (for example) the mp42hls binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9544?
CVE-2019-9544 is classified as a high-severity vulnerability due to its potential to cause Denial of Service.
How do I fix CVE-2019-9544?
To address CVE-2019-9544, update Bento4 to version 1.5.1-629 or later, which includes the necessary security patches.
What type of attack does CVE-2019-9544 allow?
CVE-2019-9544 allows attackers to exploit an out of bounds write to cause a Denial of Service, leading to application crashes.
Which versions of Bento4 are affected by CVE-2019-9544?
CVE-2019-9544 specifically affects Bento4 version 1.5.1-628.
What components of Bento4 are impacted by CVE-2019-9544?
CVE-2019-9544 impacts the AP4_CttsTableEntry component found in Core/Ap4Array.h.