Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g85x-gvx3-mq74

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted MP4 file, because access to the data structure has different expectations about layout as a result of this type confusion.

MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted MP4 file, because access to the data structure has different expectations about layout as a result of this type confusion.

EPSS

Процентиль: 68%
0.00575
Низкий

8.8 High

CVSS3

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted MP4 file, because access to the data structure has different expectations about layout as a result of this type confusion.

CVSS3: 8.8
nvd
больше 7 лет назад

MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted MP4 file, because access to the data structure has different expectations about layout as a result of this type confusion.

CVSS3: 8.8
debian
больше 7 лет назад

MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP ...

EPSS

Процентиль: 68%
0.00575
Низкий

8.8 High

CVSS3

Дефекты

CWE-704