CVE-2022-3974: Axiomatic Bento4 mp4info Ap4StdCFileByteStream.cpp ReadPartial heap-based overflow
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp of the component mp4info. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213553 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3974?
CVE-2022-3974 is a critical vulnerability found in Axiomatic Bento4 that can lead to a heap-based buffer overflow.
How does CVE-2022-3974 affect Axiomatic Bento4?
CVE-2022-3974 affects the function AP4_StdcFileByteStream::ReadPartial in the file Ap4StdCFileByteStream.cpp of the component mp4info.
What is the severity of CVE-2022-3974?
CVE-2022-3974 has a severity score of 8.8, indicating a high severity.
How can CVE-2022-3974 be exploited?
CVE-2022-3974 can be exploited through a heap-based buffer overflow attack.
Is there a fix available for CVE-2022-3974?
At the time of this writing, there is no known fix or patch available for CVE-2022-3974. It is recommended to follow the vendor's security advisories for updates.