#VU38223 Out-of-bounds read in Bento4 - CVE-2017-14645
Published: September 21, 2017 / Updated: August 8, 2020
Bento4
axiomatic-systems
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.5.0-617. The vulnerability causes an application crash, which leads to remote denial of service.