CVE-2022-3670
Axiomatic Bento4 mp42hevc WriteSample heap-based overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Axiomatic Bento4. It has been classified as critical. Affected is the function WriteSample of the component mp42hevc. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-212010 is the identifier assigned to this vulnerability.
Se ha encontrado una vulnerabilidad en Axiomatic Bento4. ha sido clasificada como crítica. Está afectada la función WriteSample del componente mp42hevc. La manipulación conlleva a un desbordamiento del buffer en la región heap de la memoria. Es posible lanzar el ataque de forma remota. La explotación ha sido divulgada al público y puede ser usada. VDB-212010 es el identificador asignado a esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-22 CVE Reserved
- 2022-10-26 CVE Published
- 2024-06-16 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-787: Out-of-bounds Write
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/axiomatic-systems/Bento4/files/9675049/Bug_3_POC.zip | 2024-08-03 | |
https://github.com/axiomatic-systems/Bento4/issues/776 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://vuldb.com/?id.212010 | 2023-11-07 |