Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-31282
HistoryJun 10, 2022 - 12:00 a.m.

CVE-2022-31282

2022-06-1000:00:00
ubuntu.com
ubuntu.com
14
bento4 mp4dump
segmentation violation
address
mp4
vulnerability
kodi
embedded copy

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

19.9%

Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via
an unknown address at /Source/C++/Core/Ap4DataBuffer.cpp:175.

Notes

Author Note
alexmurray kodi-inputstream-adaptive contains an embedded copy of bento4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

19.9%

Related for UB:CVE-2022-31282