CVE-2022-43034: Buffer Overflow
Published Oct 19, 2022
·Updated
An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4BitReader::SkipBits(unsigned int) function in mp42ts.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Event History
Oct 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-43034.
2
What software versions are affected by this vulnerability?
The affected software version is Bento4 v1.6.0-639.
3
What is the severity of CVE-2022-43034?
The severity of CVE-2022-43034 is medium with a CVSS score of 6.5.
4
What is the description of CVE-2022-43034?
CVE-2022-43034 is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBits(unsigned int) function in mp42ts in Bento4 v1.6.0-639.
5
How can I fix this vulnerability?
To fix this vulnerability, update Bento4 to a version that is not affected by CVE-2022-43034.