CVE-2024-31005: Code Injection
Published Apr 2, 2024
·Updated
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4MdhdAtom::AP4MdhdAtom,mp4fragment
Affected Software
2 affected components
Bento4 Bento4
Axiosys Bento4=1.6.0-641
Event History
Apr 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31005?
CVE-2024-31005 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2024-31005?
To fix CVE-2024-31005, users should update to the latest version of Bento4 that addresses the issue.
3
Who is affected by CVE-2024-31005?
CVE-2024-31005 affects users of Bento4 version 1.6.0-641.
4
What type of vulnerability is CVE-2024-31005?
CVE-2024-31005 is a remote code execution vulnerability.
5
What exploitation method is used in CVE-2024-31005?
CVE-2024-31005 can be exploited through the Ap4MdhdAtom.cpp code in the AP4_MdhdAtom constructor.