CVE-2022-43033: Use After Free
Published Oct 19, 2022
·Updated
An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4HdlrAtom::~AP4HdlrAtom() which allows attackers to cause a Denial of Service (DoS) via a crafted input.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Event History
Oct 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-43033?
CVE-2022-43033 is a vulnerability discovered in Bento4 1.6.0-639 that allows attackers to cause a Denial of Service (DoS) via a crafted input.
2
How severe is CVE-2022-43033?
CVE-2022-43033 has a severity rating of 6.5 (Medium).
3
Which software versions are affected by CVE-2022-43033?
Bento4 1.6.0-639 is affected by CVE-2022-43033.
4
How can the bad free vulnerability in Bento4 be exploited?
This vulnerability can be exploited by attackers through a crafted input to cause a Denial of Service (DoS).
5
Is there a fix available for CVE-2022-43033?
Currently, there is no available fix for CVE-2022-43033. It is recommended to follow the vendor's advisory for any updates or patches.