CVE-2022-43035: Medium severity Axiosys Bento4 vulnerability
An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4Dec3Atom::AP4Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42aac.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-43035?
CVE-2022-43035 is a vulnerability in Bento4 v1.6.0-639 that allows a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom, leading to a Denial of Service (DoS) when exploited.
What is the severity of CVE-2022-43035?
The severity of CVE-2022-43035 is medium with a CVSS score of 6.5.
How does CVE-2022-43035 affect Bento4?
CVE-2022-43035 affects Bento4 v1.6.0-639 and can lead to a Denial of Service (DoS) when exploited.
How can I fix CVE-2022-43035?
To fix CVE-2022-43035, it is recommended to update Bento4 to a version that includes the necessary patches or apply the appropriate security fixes provided by Axiosys.
Where can I find more information about CVE-2022-43035?
You can find more information about CVE-2022-43035 on the GitHub issue page: https://github.com/axiomatic-systems/Bento4/issues/762