Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-00388
HistoryJul 15, 2021 - 12:00 a.m.

Bento4 Denial of Service Vulnerability (CNVD-2023-00388)

2021-07-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
bento4
denial of service
mp4 files
vulnerability
memory allocation
null pointer
attacker
impact

EPSS

0.001

Percentile

40.2%

Bento4 is an open source C library for reading and writing MP4 files. Bento4 version 1.5.1-628 suffers from a denial of service vulnerability that stems from an unhandled memory allocation failure in Core/Ap48bdlAtom.cpp, resulting in a NULL pointer dereference, which could be exploited by an attacker to cause a denial of service impact.

EPSS

0.001

Percentile

40.2%

Related for CNVD-2023-00388