CVE-2022-41841: Null Pointer Dereference
Published Sep 30, 2022
·Updated
An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4File::ParseStream in Core/Ap4File.cpp, which is called from AP4File::AP4File.
Affected Software
1 affected component
Axiosys Bento4<=1.6.0-639
Event History
Sep 30, 2022
CVE Published
via MITRE·04:21 AM
Data Sourced
via MITRE·04:21 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-41841?
CVE-2022-41841 is a vulnerability in Bento4 versions up to 1.6.0-639, where a NULL pointer dereference occurs in AP4_File::ParseStream in Core/Ap4File.cpp.
2
How severe is CVE-2022-41841?
CVE-2022-41841 has a severity rating of 5.5, which is considered medium.
3
What is the affected software for CVE-2022-41841?
The affected software for CVE-2022-41841 is Axiosys Bento4 versions up to 1.6.0-639.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-41841?
The Common Weakness Enumeration (CWE) for CVE-2022-41841 is CWE-476.
5
How can I fix CVE-2022-41841?
To fix CVE-2022-41841, update Bento4 to a version beyond 1.6.0-639.