๐Ÿ” CVE Alert

CVE-2022-4584

MEDIUM 6.3

Axiomatic Bento4 mp42aac heap-based overflow

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-639. It has been rated as critical. Affected by this issue is some unknown functionality of the component mp42aac. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-216170 is the identifier assigned to this vulnerability.

CWE CWE-122
Vendor axiomatic
Product bento4
Published Dec 17, 2022
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for axiomatic bento4

Be the first to know when new medium vulnerabilities affecting axiomatic bento4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Axiomatic / Bento4
1.6.0-639

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.216170 vuldb.com: https://vuldb.com/?ctiid.216170 github.com: https://github.com/axiomatic-systems/Bento4/issues/818 github.com: https://github.com/axiomatic-systems/Bento4/files/10095915/POC2.tar.gz