First published: Wed Oct 26 2022(Updated: )
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212006 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Axiosys Bento4 | =1.6.0-639 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-3666 is high (7.8).
The affected software of CVE-2022-3666 is Axiosys Bento4 version 1.6.0-639.
The CWE of CVE-2022-3666 is CWE-416 and CWE-119.
CVE-2022-3666 can be remotely exploited.
The fix for CVE-2022-3666 may be available through Axiosys Bento4 version 1.6.0-640 or newer.