First published: Mon Oct 03 2022(Updated: )
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axiosys Bento4 | =1.6.0-639 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41428 is a vulnerability in Bento4 v1.6.0-639 that allows a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
Bento4 v1.6.0-639 is the affected software version for CVE-2022-41428.
CVE-2022-41428 has a severity score of 8.8, indicating it is a high severity vulnerability.
To fix CVE-2022-41428, it is recommended to update Bento4 to a version that addresses the vulnerability.
More information about CVE-2022-41428 can be found at the following reference: [GitHub Issue #773](https://github.com/axiomatic-systems/Bento4/issues/773).