MEDIUM
Axiomatic Bento4 mp4edit Create memory leak
Published Oct 26, 2022
5.5
MEDIUMCVSS 3.1
EPSS 0.72%
Description
A vulnerability was found in Axiomatic Bento4 and classified as problematic. This issue affects the function AP4_AvccAtom::Create of the component mp4edit. The manipulation leads to memory leak. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212009 was assigned to this vulnerability.
Affected products
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43028 Advisory
- https://github.com/axiomatic-systems/Bento4/files/9675042/Bug_2_POC.zip ExploitThird Party Advisory
- https://github.com/axiomatic-systems/Bento4/issues/776 ExploitThird Party Advisory
- https://vuldb.com/?id.212009 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43028 | Advisory | |
| https://github.com/axiomatic-systems/Bento4/files/9675042/Bug_2_POC.zip | ExploitThird Party Advisory | |
| https://github.com/axiomatic-systems/Bento4/issues/776 | ExploitThird Party Advisory | |
| https://vuldb.com/?id.212009 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Oct 26, 2022
Updated Apr 14, 2025
Reserved Oct 22, 2022
Link CVE-2022-3669
CISA Vulnrichment
Updated Apr 14, 2025
ENISA EUVD
EUVD-2022-43028 Assigner VulDB
Published Oct 26, 2022
Updated Apr 14, 2025
Exploited since n/a
Link EUVD-2022-43028