CVE-2025-25942: Infoleak
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
bento4/mp4fragmentto a version that resolves this vulnerability.Fixed in v1.6.0-641
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25942?
The severity of CVE-2025-25942 is classified as moderate due to its potential to expose sensitive information.
How do I fix CVE-2025-25942?
To fix CVE-2025-25942, update to the latest version of Bento4 that addresses this vulnerability.
What specific issue does CVE-2025-25942 highlight in Bento4?
CVE-2025-25942 highlights a memory management issue in the mp4fragment tool that can lead to information disclosure.
Can CVE-2025-25942 be exploited by an attacker?
Yes, CVE-2025-25942 can be exploited by an attacker who processes invalid files through the mp4fragment tool.
Which versions of Bento4 are affected by CVE-2025-25942?
CVE-2025-25942 affects all versions of Bento4 prior to the fix implemented in later releases.