#VU16745 Resource exhaustion in Bento4 - CVE-2018-20095
Published: December 27, 2018
Bento4
axiomatic-systems
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to excessive memory allocation in EnsureCapacity in Core/Ap4Array.h. A remote attacker can supply specially crafted MP4 file, trigger resource exhaustion, as demonstrated by mp42hls and perform a denial of service (DoS) attack.