First published: Wed Feb 19 2025(Updated: )
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libgcc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-25942 is classified as moderate due to its potential to expose sensitive information.
To fix CVE-2025-25942, update to the latest version of Bento4 that addresses this vulnerability.
CVE-2025-25942 highlights a memory management issue in the mp4fragment tool that can lead to information disclosure.
Yes, CVE-2025-25942 can be exploited by an attacker who processes invalid files through the mp4fragment tool.
CVE-2025-25942 affects all versions of Bento4 prior to the fix implemented in later releases.