Axiomatic Bento4 avcinfo Ap4BitStream.cpp WriteBytes heap-based overflow
CVE-2022-3664

7.3HIGH

Key Information:

Vendor

Axiomatic

Status
Vendor
CVE Published:
26 October 2022

What is CVE-2022-3664?

A vulnerability classified as critical has been found in Axiomatic Bento4. Affected is the function AP4_BitStream::WriteBytes of the file Ap4BitStream.cpp of the component avcinfo. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212004.

Affected Version(s)

Bento4

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.