CVE-2022-41429: High severity Axiosys Bento4 vulnerability
Published Oct 3, 2022
·Updated
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4Atom::TypeFromString function in mp4tag.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Remediation
Patch Available
Event History
Oct 3, 2022
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-41429?
CVE-2022-41429 is a vulnerability discovered in Bento4 v1.6.0-639, which allows for a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.
2
What is the severity of CVE-2022-41429?
The severity of CVE-2022-41429 is high with a CVSS score of 8.8.
3
How does CVE-2022-41429 impact Axiosys Bento4 v1.6.0-639?
CVE-2022-41429 impacts Axiosys Bento4 v1.6.0-639 by introducing a heap overflow vulnerability via the AP4_Atom::TypeFromString function in mp4tag.
4
Is there a fix available for CVE-2022-41429?
Yes, a fix for CVE-2022-41429 can be found in the GitHub repository of Axiosys Bento4.
5
Where can I find more information about CVE-2022-41429?
More information about CVE-2022-41429 can be found in the GitHub issue tracker for Axiosys Bento4.