#VU38221 Out-of-bounds read in Bento4 - CVE-2017-14643
Published: September 21, 2017 / Updated: August 8, 2020
Bento4
axiomatic-systems
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over-read and application crash in AP4_BytesToUInt32BE in Core/Ap4Utils.h.