#VU36188 Resource exhaustion in Bento4 - CVE-2019-6966
Published: January 26, 2019 / Updated: August 8, 2020
Bento4
axiomatic-systems
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
An issue was discovered in Bento4 1.5.1-628. The AP4_ElstAtom class in Core/Ap4ElstAtom.cpp has an attempted excessive memory allocation related to AP4_Array<AP4_ElstEntry>::EnsureCapacity in Core/Ap4Array.h, as demonstrated by mp42hls.