CVE-2024-30809: Use After Free
Published Apr 2, 2024
·Updated
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated by mp42ts.
Affected Software
2 affected components
Bento4 Bento4
Axiosys Bento4=1.6.0-641
Event History
Apr 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30809?
CVE-2024-30809 is classified as a Denial of Service (DoS) vulnerability.
2
How does CVE-2024-30809 affect Bento4?
CVE-2024-30809 causes a heap-use-after-free condition in Bento4 that can lead to a Denial of Service.
3
What software versions are affected by CVE-2024-30809?
CVE-2024-30809 affects Bento4 version 1.6.0-641-2-g1529b83.
4
How do I fix CVE-2024-30809?
To fix CVE-2024-30809, update to the latest version of Bento4 that contains the patched code.
5
What should I do if I cannot update due to CVE-2024-30809?
If you cannot update, consider implementing additional access controls and monitoring to mitigate the effects of CVE-2024-30809.