CVE-2022-40439: Medium severity Axiosys Bento4 vulnerability
Published Sep 14, 2022
·Updated
An memory leak issue was discovered in AP4StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers to cause a denial of service via a crafted file.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Event History
Sep 14, 2022
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-40439?
CVE-2022-40439 is classified as a denial of service vulnerability due to a memory leak in Bento4.
2
How do I fix CVE-2022-40439?
To fix CVE-2022-40439, upgrade Bento4 to a version later than 1.6.0-639.
3
What software is affected by CVE-2022-40439?
CVE-2022-40439 affects Bento4 version 1.6.0-639.
4
What type of attack does CVE-2022-40439 enable?
CVE-2022-40439 can be exploited to cause a denial of service via a crafted file.
5
What component of Bento4 is vulnerable in CVE-2022-40439?
The vulnerability in CVE-2022-40439 is found in the AP4_StdcFileByteStream::Create function.