CVE-2022-3812
Axiomatic Bento4 mp4encrypt AP4_ContainerAtom memory leak
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212678 is the identifier assigned to this vulnerability.
Se encontró una vulnerabilidad en Axiomatic Bento4. Ha sido calificado como problemático. La función AP4_ContainerAtom::AP4_ContainerAtom del componente mp4encrypt es afectada por esta vulnerabilidad. La manipulación conduce a una pérdida de memoria. El ataque puede lanzarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-212678 es el identificador asignado a esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-01 CVE Reserved
- 2022-11-01 CVE Published
- 2024-06-22 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-401: Missing Release of Memory after Effective Lifetime
- CWE-404: Improper Resource Shutdown or Release
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/axiomatic-systems/Bento4/issues/792 | Issue Tracking | |
https://vuldb.com/?id.212678 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/axiomatic-systems/Bento4/files/9726934/POC_mp4encrypt_631000973.zip | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|