First published: Thu Sep 15 2022(Updated: )
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4_EsDescriptor::WriteFields and AP4_Expandable::Write.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axiosys Bento4 | <=1.6.0-639 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40738 is a vulnerability discovered in Bento4 through version 1.6.0-639, which allows a NULL pointer dereference to occur in AP4_DescriptorListWriter::Action.
CVE-2022-40738 has a severity score of 6.5, which is classified as medium.
Axiosys Bento4 version 1.6.0-639 is affected by CVE-2022-40738.
CVE-2022-40738 is associated with CWE-476, which is the NULL Pointer Dereference vulnerability.
At the moment, there is no known fix or patch available for CVE-2022-40738. It is recommended to follow the security advisory for any updates on fixes.