CVE-2022-3670: Axiomatic Bento4 mp42hevc WriteSample heap-based overflow
A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212010 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3670?
The severity of CVE-2022-3670 is classified as high, with a CVSSv3 score of 7.8.
How does CVE-2022-3670 affect the Axiomatic Bento4 software?
CVE-2022-3670 affects the WriteSample function of the mp42hevc component in Axiomatic Bento4, leading to a heap-based buffer overflow.
Can CVE-2022-3670 be exploited remotely?
Yes, CVE-2022-3670 can be exploited remotely.
Is there a known exploit for CVE-2022-3670?
Yes, a proof of concept exploit for CVE-2022-3670 has been disclosed to the public.
How can I fix CVE-2022-3670 in Axiomatic Bento4?
To fix CVE-2022-3670, update Axiomatic Bento4 to version 1.6.0-639 or later.