First published: Thu Sep 15 2022(Updated: )
An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::WritePartial located in System/StdC/Ap4StdCFileByteStream.cpp, called from AP4_ByteStream::Write and AP4_HdlrAtom::WriteFields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axiosys Bento4 | <=1.6.0-639 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40737 is a vulnerability in Bento4 through version 1.6.0-639 that allows a buffer over-read in the AP4_StdcFileByteStream::WritePartial function.
CVE-2022-40737 has a severity rating of 6.5 (medium).
CVE-2022-40737 affects Bento4 versions up to and including 1.6.0-639.
To fix CVE-2022-40737, it is recommended to update Bento4 to a version newer than 1.6.0-639.
Yes, you can find more details about CVE-2022-40737 at the following link: [GitHub issue #756](https://github.com/axiomatic-systems/Bento4/issues/756).