In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
oryginał ENCVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HTechsmith Mp4v2
APPTechsmith2.0.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2018-14403CRITICAL9.8PL ✓ten sam produkt
MP4v2: type confusion w MP4NameFirstMatches prowadząca do out-of-bounds memory access
CVE-2018-14054CRITICAL9.8PL ✓ten sam produkt
Double free w klasie MP4StringProperty biblioteki MP4v2 2.0.0
CVE-2018-14446HIGH8.8ten sam produkt
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of servic...
CVE-2018-14379HIGH8.8ten sam produkt
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case wh...
CVE-2018-14326HIGH8.8ten sam produkt
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the...