CVE-2022-41428: High severity Axiosys Bento4 vulnerability
Published Oct 3, 2022
·Updated
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4BitReader::ReadBits function in mp4mux.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Event History
Oct 3, 2022
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-41428?
CVE-2022-41428 is a vulnerability in Bento4 v1.6.0-639 that allows a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
2
What software versions are affected by CVE-2022-41428?
Bento4 v1.6.0-639 is the affected software version for CVE-2022-41428.
3
How severe is CVE-2022-41428?
CVE-2022-41428 has a severity score of 8.8, indicating it is a high severity vulnerability.
4
How can I fix CVE-2022-41428?
To fix CVE-2022-41428, it is recommended to update Bento4 to a version that addresses the vulnerability.
5
Where can I find more information about CVE-2022-41428?
More information about CVE-2022-41428 can be found at the following reference: [GitHub Issue #773](https://github.com/axiomatic-systems/Bento4/issues/773).