CVE-2024-24155: Medium severity bento4 vulnerability
Published Feb 28, 2024
·Updated
Bento4 v1.5.1-628 contains a Memory leak on AP4Movie::AP4Movie, parsing tracks and added into mTracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
Affected Software
1 affected component
Axiosys Bento4=1.5.1-628
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-24155?
CVE-2024-24155 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2024-24155?
To fix CVE-2024-24155, update to a patched version of Bento4 that addresses the memory leak.
3
What type of attack can occur due to CVE-2024-24155?
CVE-2024-24155 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
4
What component of Bento4 is affected by CVE-2024-24155?
CVE-2024-24155 affects the AP4_Movie class in Bento4 during the parsing of tracks.
5
Is CVE-2024-24155 specific to a certain version of Bento4?
Yes, CVE-2024-24155 specifically affects Bento4 version 1.5.1-628.