CVE-2022-27607: High severity bento4 vulnerability
Published Mar 21, 2022
·Updated
Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4HvccAtom class, a different issue than CVE-2018-14531.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Event History
Mar 21, 2022
CVE Published
via MITRE·10:06 PM
Data Sourced
via MITRE·10:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-27607?
CVE-2022-27607 is classified as a moderate severity vulnerability due to potential impacts from heap-based buffer over-read.
2
How do I fix CVE-2022-27607?
To fix CVE-2022-27607, upgrade to a version of Bento4 later than 1.6.0-639 that addresses the vulnerability.
3
What versions of Bento4 are affected by CVE-2022-27607?
CVS-2022-27607 specifically affects Bento4 version 1.6.0-639.
4
What type of vulnerability is CVE-2022-27607?
CVE-2022-27607 is a heap-based buffer over-read vulnerability.
5
Does CVE-2022-27607 affect any other versions of Bento4 besides 1.6.0-639?
CVE-2022-27607 is only reported to affect Bento4 version 1.6.0-639 and does not impact other versions.