
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2020-29245) affects dhowden tag library versions before 2020-11-19. The vulnerability allows a 'panic: runtime error: slice bounds out of range' via readAtomData function. This issue was discovered and reported on November 19, 2020 (GitHub Issue).
The vulnerability exists in the readAtomData function within mp4.go file. The issue occurs when processing MP4 files with specific atom data sizes. Specifically, when the size of buffer 'b' is 3, the program will panic due to attempting to access slice bounds [:4] with a capacity of 3. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (MEDIUM) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (NVD).
When exploited, this vulnerability leads to a program panic, effectively causing a denial of service condition. The impact is limited to availability, with no direct impact on confidentiality or integrity of the system (NVD).
The vulnerability can be triggered by providing specially crafted MP4 files with specific atom data sizes. A proof-of-concept test case has been provided demonstrating the vulnerability (GitHub Issue).
The vulnerability has been fixed in versions released after 2020-11-19. Users should upgrade to a version released after this date to mitigate the vulnerability (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."