#VU38224 Out-of-bounds read in Bento4 - CVE-2017-14646
Published: September 21, 2017 / Updated: August 8, 2020
Bento4
axiomatic-systems
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer over-read and application crash in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.