Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wr4v-2x2x-cprg

Опубликовано: 20 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.

EPSS

Процентиль: 33%
0.0013
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
12 месяцев назад

An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.

EPSS

Процентиль: 33%
0.0013
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-200