
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-3669 is a vulnerability discovered in Bento4, affecting both the master branch (5b7cc25) and the latest release version (1.6.0-639). The issue was reported on September 25, 2022, by security researchers from NCNIPC of China (GitHub Issue).
The vulnerability manifests as a heap-buffer-overflow in the mp42hevc binary. Specifically, the issue occurs in the WriteSample function where there is a READ operation of size 1 at address 0x6020000002d4, which is located 0 bytes to the right of a 4-byte region. The bug is triggered when processing certain malformed MP4 files (GitHub Issue).
When exploited, this vulnerability can lead to heap buffer overflow conditions, which could potentially result in program crashes, memory corruption, or possible code execution. The issue affects the mp42hevc component of Bento4, which is used for video processing (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."