CVE-2022-40738: Null Pointer Dereference
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4DescriptorListWriter::Action in Core/Ap4Descriptor.h, called from AP4EsDescriptor::WriteFields and AP4Expandable::Write.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40738?
CVE-2022-40738 is a vulnerability discovered in Bento4 through version 1.6.0-639, which allows a NULL pointer dereference to occur in AP4_DescriptorListWriter::Action.
How severe is CVE-2022-40738?
CVE-2022-40738 has a severity score of 6.5, which is classified as medium.
Which software is affected by CVE-2022-40738?
Axiosys Bento4 version 1.6.0-639 is affected by CVE-2022-40738.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-40738?
CVE-2022-40738 is associated with CWE-476, which is the NULL Pointer Dereference vulnerability.
Is there a fix available for CVE-2022-40738?
At the moment, there is no known fix or patch available for CVE-2022-40738. It is recommended to follow the security advisory for any updates on fixes.