Memory Leak Vulnerability in Bento4 by Axiomatic Systems
CVE-2025-25946

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 February 2025

What is CVE-2025-25946?

A memory leak issue exists in Bento4 version 1.6.0-641 that could be exploited by an attacker through specially crafted MP4 input files. The vulnerability occurs within the functions AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, affecting the execution of mp4encrypt. This flaw may lead to resource exhaustion, potentially impacting the performance of applications utilizing the affected version of Bento4 for video processing.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.