First published: Wed Feb 28 2024(Updated: )
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-628 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24155 is classified as a Denial of Service (DoS) vulnerability.
To fix CVE-2024-24155, update to a patched version of Bento4 that addresses the memory leak.
CVE-2024-24155 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
CVE-2024-24155 affects the AP4_Movie class in Bento4 during the parsing of tracks.
Yes, CVE-2024-24155 specifically affects Bento4 version 1.5.1-628.