CVE-2018-20095

An issue was discovered in EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt at excessive memory allocation, as demonstrated by mp42hls.
References
Link Resource
https://github.com/axiomatic-systems/Bento4/issues/341 Exploit Third Party Advisory
https://github.com/axiomatic-systems/Bento4/issues/341 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:axiosys:bento4:1.5.1-627:*:*:*:*:*:*:*

History

21 Nov 2024, 04:00

Type Values Removed Values Added
References () https://github.com/axiomatic-systems/Bento4/issues/341 - Exploit, Third Party Advisory () https://github.com/axiomatic-systems/Bento4/issues/341 - Exploit, Third Party Advisory

Information

Published : 2018-12-12 10:29

Updated : 2024-11-21 04:00


NVD link : CVE-2018-20095

Mitre link : CVE-2018-20095

CVE.ORG link : CVE-2018-20095


JSON object : View

Products Affected

axiosys

  • bento4
CWE
CWE-770

Allocation of Resources Without Limits or Throttling