CVE-2022-3662
Summary
| CVE | CVE-2022-3662 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-26 19:15:00 UTC |
| Updated | 2023-11-07 03:51:00 UTC |
| Description | A vulnerability was found in Axiomatic Bento4. It has been declared as critical. This vulnerability affects the function GetOffset of the file Ap4Sample.h of the component mp42hls. The manipulation leads to use after free. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-212002 is the identifier assigned to this vulnerability. |
Risk And Classification
Problem Types: CWE-416
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/axiomatic-systems/Bento4/files/9817606/mp42hls_cuaf_Ap4Sample... | MISC | github.com | |
| CVE-2022-3662 | Axiomatic Bento4 mp42hls Ap4Sample.h GetOffset use after free (ID 802) | MISC | vuldb.com | |
| Concurrent heap use after free in mp42hls, GetOffset, Ap4Sample.h:99 · Issue #802 · axiomatic-systems/Bento4 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.