CVE-2023-29576: Medium severity bento4 vulnerability
Published Apr 11, 2023
·Updated
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Event History
Apr 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-29576?
The severity of CVE-2023-29576 is medium with a severity value of 5.5.
2
How does Bento4 v1.6.0-639 contain a segmentation violation?
Bento4 v1.6.0-639 contains a segmentation violation through the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.
3
Which software versions are affected by CVE-2023-29576?
The affected software version is Bento4 v1.6.0-639.
4
Is there a fix available for CVE-2023-29576?
At the moment, no fix has been provided for CVE-2023-29576.
5
Where can I find more information about CVE-2023-29576?
You can find more information about CVE-2023-29576 at the following references: [GitHub Issue #844](https://github.com/axiomatic-systems/Bento4/issues/844) and [GitHub](https://github.com/z1r00/fuzz_vuln/blob/main/Bento4/mp4decrypt/sigv/readme.md).