CVE-2022-40737: Medium severity Axiosys Bento4 vulnerability
An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4ByteStream::Write and AP4HdlrAtom::WriteFields.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40737?
CVE-2022-40737 is a vulnerability in Bento4 through version 1.6.0-639 that allows a buffer over-read in the AP4_StdcFileByteStream::WritePartial function.
How severe is CVE-2022-40737?
CVE-2022-40737 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2022-40737?
CVE-2022-40737 affects Bento4 versions up to and including 1.6.0-639.
How can I fix CVE-2022-40737?
To fix CVE-2022-40737, it is recommended to update Bento4 to a version newer than 1.6.0-639.
Is there any additional information available about CVE-2022-40737?
Yes, you can find more details about CVE-2022-40737 at the following link: [GitHub issue #756](https://github.com/axiomatic-systems/Bento4/issues/756).