CVE-2022-3785: Axiomatic Bento4 Avcinfo SetDataSize heap-based overflow
A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4DataBuffer::SetDataSize of the component Avcinfo. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212564.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3785?
CVE-2022-3785 is a critical vulnerability found in Axiomatic Bento4, specifically in the function AP4_DataBuffer::SetDataSize of the component Avcinfo, which leads to a heap-based buffer overflow.
How severe is CVE-2022-3785?
CVE-2022-3785 has a severity score of 7.8, which is considered high.
Is CVE-2022-3785 exploitable remotely?
Yes, CVE-2022-3785 can be exploited remotely.
Which software versions are affected by CVE-2022-3785?
The affected software version of Axiomatic Bento4 is 1.6.0-639.
How can I fix CVE-2022-3785?
To fix CVE-2022-3785, it is recommended to update Axiomatic Bento4 to a version that includes the necessary security patches.