CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
59.3%
A vulnerability classified as critical was found in Axiomatic Bento4.
Affected by this vulnerability is the function
AP4_StdcFileByteStream::ReadPartial of the file Ap4StdCFileByteStream.cpp
of the component mp4info. The manipulation leads to heap-based buffer
overflow. The attack can be launched remotely. The exploit has been
disclosed to the public and may be used. The identifier VDB-213553 was
assigned to this vulnerability.
Author | Note |
---|---|
alexmurray | kodi-inputstream-adaptive contains an embedded copy of bento4 |
eslerm | CVE possibly assigned based on commit message |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 22.04 | noarch | kodi-inputstream-adaptive | < any | UNKNOWN |
ubuntu | 24.04 | noarch | kodi-inputstream-adaptive | < any | UNKNOWN |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
59.3%