First published: Wed Oct 19 2022(Updated: )
An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Axiosys Bento4 | =1.6.0-639 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43035 is a vulnerability in Bento4 v1.6.0-639 that allows a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom, leading to a Denial of Service (DoS) when exploited.
The severity of CVE-2022-43035 is medium with a CVSS score of 6.5.
CVE-2022-43035 affects Bento4 v1.6.0-639 and can lead to a Denial of Service (DoS) when exploited.
To fix CVE-2022-43035, it is recommended to update Bento4 to a version that includes the necessary patches or apply the appropriate security fixes provided by Axiosys.
You can find more information about CVE-2022-43035 on the GitHub issue page: https://github.com/axiomatic-systems/Bento4/issues/762