CVE-2023-38666: Medium severity bento4 vulnerability
Published Aug 22, 2023
·Updated
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4Processor::ProcessFragments function in mp4encrypt.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-639
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-38666?
CVE-2023-38666 is a vulnerability in Bento4 v1.6.0-639 that causes a segmentation violation in the AP4_Processor::ProcessFragments function in mp4encrypt.
2
How severe is CVE-2023-38666?
CVE-2023-38666 has a severity score of 5.5, which is considered medium.
3
What software is affected by CVE-2023-38666?
The Bento4 v1.6.0-639 software by Axiosys is affected by CVE-2023-38666.
4
What is the fix for CVE-2023-38666?
To fix CVE-2023-38666, users should update to a version of Bento4 that does not contain the vulnerability.
5
Where can I find more information about CVE-2023-38666?
More information about CVE-2023-38666 can be found at the following reference: [link](https://github.com/axiomatic-systems/Bento4/issues/784)