HIGH
Axiomatic Bento4 mp42aac Ap4ByteStream.cpp WritePartial heap-based overflow
Published Oct 26, 2022
7.5
HIGHCVSS 3.1
EPSS 1.19%
Description
A vulnerability, which was classified as critical, was found in Axiomatic Bento4. This affects the function AP4_MemoryByteStream::WritePartial of the file Ap4ByteStream.cpp of the component mp42aac. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212007.
Affected products
-
Affected
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43026 Advisory
- https://github.com/17ssDP/fuzzer_crashes/blob/main/Bento4/mp42aac-hbo-01 ExploitThird Party Advisory
- https://github.com/axiomatic-systems/Bento4/issues/789 ExploitThird Party Advisory
- https://vuldb.com/?id.212007 Permissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43026 | Advisory | |
| https://github.com/17ssDP/fuzzer_crashes/blob/main/Bento4/mp42aac-hbo-01 | ExploitThird Party Advisory | |
| https://github.com/axiomatic-systems/Bento4/issues/789 | ExploitThird Party Advisory | |
| https://vuldb.com/?id.212007 | Permissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Oct 26, 2022
Updated Apr 14, 2025
Reserved Oct 22, 2022
Link CVE-2022-3667
CISA Vulnrichment
Updated Apr 14, 2025
Red Hat
No data
GitHub
No data