Heap-Based Buffer Overflow in Axiomatic Bento4 Multimedia Software
CVE-2025-0753

6.9MEDIUM

Key Information:

Vendor
Axiomatic
Status
Bento4
Vendor
CVE Published:
27 January 2025

Badges

👾 Exploit Exists

Summary

A significant security vulnerability has been identified in Axiomatic Bento4, specifically within the mp42aac component's ReadPartial function. This flaw could allow an attacker to exploit the software's handling of data streams, leading to a heap-based buffer overflow. As a result, malicious actors are capable of remotely executing attacks by manipulating input data, which could compromise the integrity of systems utilizing this software. Immediate action is recommended to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Bento4 1.0

Bento4 1.1

Bento4 1.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhang Yaoliang (VulDB User)
.