HIGH
Axiomatic Bento4 avcinfo AvcInfo.cpp heap-based overflow
Published Oct 26, 2022
7.8
HIGHCVSS 3.1
EPSS 0.74%
Description
A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is an unknown functionality of the file AvcInfo.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212005 was assigned to this vulnerability.
Affected products
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- https://github.com/axiomatic-systems/Bento4/files/9746311/avcinfo_poc2.zip ExploitThird Party Advisory
- https://github.com/axiomatic-systems/Bento4/issues/794 ExploitThird Party Advisory
- https://vuldb.com/?id.212005 Permissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/axiomatic-systems/Bento4/files/9746311/avcinfo_poc2.zip | ExploitThird Party Advisory | |
| https://github.com/axiomatic-systems/Bento4/issues/794 | ExploitThird Party Advisory | |
| https://vuldb.com/?id.212005 | Permissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Oct 26, 2022
Updated Apr 14, 2025
Reserved Oct 22, 2022
Link CVE-2022-3665
CISA Vulnrichment
Updated Apr 14, 2025