CVE-2025-25946: Infoleak
An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4MarlinIpmpEncryptingProcessor::Initialize and AP4Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25946?
CVE-2025-25946 is considered a medium severity vulnerability due to the potential for a memory leak.
How do I fix CVE-2025-25946?
To fix CVE-2025-25946, update Bento4 to a version later than v1.6.0-641 where this vulnerability is patched.
What components are affected by CVE-2025-25946?
CVE-2025-25946 affects the AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process components of Bento4.
What type of attack can exploit CVE-2025-25946?
CVE-2025-25946 can be exploited through a specially crafted MP4 input file that causes a memory leak during processing.
Is CVE-2025-25946 specific to a certain version of Bento4?
Yes, CVE-2025-25946 specifically affects Bento4 version v1.6.0-641.