Stack-Based Buffer Over-Read in MediaInfo by MediaArea
CVE-2020-15395

7.8HIGH

Key Information:

Vendor

Mediaarea

Status
Vendor
CVE Published:
30 June 2020

What is CVE-2020-15395?

MediaInfo, developed by MediaArea, is affected by a stack-based buffer over-read occurring within the Streams_Fill_PerStream function in the file Multiple/File_MpegPs.cpp, specifically during the parsing of MpegPs. This vulnerability can lead to potential information disclosure and unintended access to sensitive data under specific conditions, thereby posing a threat to the integrity of the software. Users are advised to be cautious and update to the latest version to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.