Information Disclosure Vulnerability in Bento4 by Axiomatic Systems
CVE-2025-25942

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 February 2025

What is CVE-2025-25942?

An issue in Bento4 v1.6.0-641 can potentially expose sensitive information through the mp4fragment tool when handling invalid files. This flaw arises from improper management of memory allocation in the SampleArray::SampleArray within Mp4Fragment.cpp, which can lead to unintentional information leakage. Developers and users of Bento4 should be aware of this risk and ensure that they handle file inputs carefully to mitigate possible exploitation.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-25942 : Information Disclosure Vulnerability in Bento4 by Axiomatic Systems