
Cloud Vulnerability DB
A community-led vulnerabilities database
Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h (NVD, GitHub Issue). The vulnerability was disclosed on April 11, 2023.
The vulnerability exists in the AP4_TrunAtom::SetDataOffset(int) function located in Ap4TrunAtom.h. When triggered, it causes a segmentation violation due to a WRITE memory access to address 0x000000000028, which points to the zero page. The issue occurs during the processing of MP4 files in the mp4decrypt component. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 MEDIUM (Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) (NVD).
The vulnerability can lead to a denial of service condition through application crash when processing specially crafted MP4 files. The CVSS scoring indicates high impact on availability but no impact on confidentiality or integrity (NVD).
The vulnerability can be triggered by processing a specially crafted MP4 file through the mp4decrypt component. A proof of concept exploit has been published demonstrating the vulnerability (GitHub Issue, POC Details).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."