First published: Mon Oct 31 2022(Updated: )
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212564.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Axiosys Bento4 | =1.6.0-639 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3785 is a critical vulnerability found in Axiomatic Bento4, specifically in the function AP4_DataBuffer::SetDataSize of the component Avcinfo, which leads to a heap-based buffer overflow.
CVE-2022-3785 has a severity score of 7.8, which is considered high.
Yes, CVE-2022-3785 can be exploited remotely.
The affected software version of Axiomatic Bento4 is 1.6.0-639.
To fix CVE-2022-3785, it is recommended to update Axiomatic Bento4 to a version that includes the necessary security patches.