CWE
401 404
Advisory Published
Updated

CVE-2022-3815: Axiomatic Bento4 mp4decrypt memory leak

First published: Tue Nov 01 2022(Updated: )

A vulnerability, which was classified as problematic, has been found in Axiomatic Bento4. This issue affects some unknown processing of the component mp4decrypt. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212681 was assigned to this vulnerability.

Credit: cna@vuldb.com

Affected SoftwareAffected VersionHow to fix
Axiosys Bento4=1.6.0-639

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2022-3815?

    CVE-2022-3815 is a vulnerability found in Axiomatic Bento4 that allows for remote initiation of an attack and can result in a memory leak through the mp4decrypt component.

  • How severe is CVE-2022-3815?

    CVE-2022-3815 is classified as a medium severity vulnerability with a severity value of 6.5.

  • What is affected by CVE-2022-3815?

    Axiomatic Bento4 version 1.6.0-639 is affected by CVE-2022-3815.

  • How can CVE-2022-3815 be exploited?

    CVE-2022-3815 can be exploited remotely by manipulating the mp4decrypt component, leading to a memory leak.

  • Is there a fix available for CVE-2022-3815?

    At the time of writing, there is no known fix available for CVE-2022-3815. It is recommended to follow the recommendations provided by the vendor or the official sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203