CVE-2025-25945: Infoleak
Published Feb 19, 2025
·Updated
An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.
Affected Software
2 affected components
Bento4 Bento4
Axiosys Bento4=1.6.0-641
Event History
Feb 19, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25945?
CVE-2025-25945 has a moderate severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2025-25945?
To fix CVE-2025-25945, update Bento4 to the latest version that addresses this vulnerability.
3
What type of information can be exposed by CVE-2025-25945?
CVE-2025-25945 can expose sensitive information processed by the affected functions in Bento4.
4
Which versions of Bento4 are affected by CVE-2025-25945?
CVE-2025-25945 affects Bento4 version 1.6.0-641 and possibly earlier versions.
5
How is CVE-2025-25945 exploited?
CVE-2025-25945 can be exploited by an attacker sending malicious input that triggers the vulnerability in Mp4Fragment.cpp.