CVE-2022-41430: High severity Axiosys Bento4 vulnerability
Published Oct 3, 2022
·Updated
Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4BitReader::ReadBit function in mp4mux.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Remediation
Patch Available
Event History
Oct 3, 2022
CVE Published
via MITRE·01:51 PM
Data Sourced
via MITRE·01:51 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-41430?
CVE-2022-41430 is a vulnerability discovered in Bento4 v1.6.0-639 that allows a heap overflow through the AP4_BitReader::ReadBit function in mp4mux.
2
How severe is CVE-2022-41430?
CVE-2022-41430 has a severity rating of 8.8 (high).
3
Which software versions are affected by CVE-2022-41430?
CVE-2022-41430 affects Bento4 v1.6.0-639.
4
How can I fix CVE-2022-41430?
To fix CVE-2022-41430, it is recommended to update Bento4 to a version that includes the necessary security patches.
5
Where can I find more information about CVE-2022-41430?
More information about CVE-2022-41430 can be found at the following reference: [GitHub - Bento4 Issue #773](https://github.com/axiomatic-systems/Bento4/issues/773)