6.5

CVE-2022-3813

Axiomatic Bento4 mp4edit memory leak

A vulnerability classified as problematic has been found in Axiomatic Bento4. This affects an unknown part of the component mp4edit. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-212679.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AxiosysBento4 Version1.6.0-639
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.494
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
cna@vuldb.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE-404 Improper Resource Shutdown or Release

The product does not release or incorrectly releases a resource before it is made available for re-use.

https://github.com/axiomatic-systems/Bento4/issues/792
Third Party Advisory
https://github.com/axiomatic-systems/Bento4/files/9726974/POC_mp4edit_728838793.zip
Third Party Advisory
https://vuldb.com/?id.212679
Third Party Advisory