CVE-2025-0753: Axiomatic Bento4 mp42aac ReadPartial heap-based overflow
Published Jan 27, 2025
·Updated
A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4StdcFileByteStream::ReadPartial of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Axiomatic Bento4<=1.6.0
Axiosys Bento4<=1.6.0
Event History
Jan 27, 2025
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0753?
CVE-2025-0753 is classified as a critical vulnerability.
2
How do I fix CVE-2025-0753?
To fix CVE-2025-0753, upgrade Axiomatic Bento4 to version 1.6.1 or later.
3
What type of vulnerability is CVE-2025-0753?
CVE-2025-0753 is a heap-based buffer overflow vulnerability.
4
Can CVE-2025-0753 be exploited remotely?
Yes, CVE-2025-0753 can be initiated remotely by an attacker.
5
Which component of Axiomatic Bento4 is affected by CVE-2025-0753?
CVE-2025-0753 affects the mp42aac component through the function AP4_StdcFileByteStream::ReadPartial.