CVE-2024-25451: Medium severity Axiosys Bento4 vulnerability
Published Feb 9, 2024
·Updated
Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4DataBuffer::ReallocateBuffer() function.
Affected Software
1 affected component
Axiosys Bento4=1.6.0-640
Event History
Feb 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25451?
CVE-2024-25451 has been classified as a high-severity vulnerability due to its out-of-memory bug that can lead to application crashes.
2
How do I fix CVE-2024-25451?
To fix CVE-2024-25451, update Bento4 to the latest version that mitigates the out-of-memory issue.
3
What is the impact of CVE-2024-25451 on Bento4?
The impact of CVE-2024-25451 includes potential application instability and crashes when handling data.
4
Is CVE-2024-25451 exploitable remotely?
Yes, CVE-2024-25451 can potentially be exploited remotely if an attacker can send specially crafted data to the affected Bento4 application.
5
What components of Bento4 are affected by CVE-2024-25451?
CVE-2024-25451 specifically affects the AP4_DataBuffer::ReallocateBuffer() function in Bento4 version 1.6.0-640.