MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted MP4 file, because access to the data structure has different expectations about layout as a result of this type confusion.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HTechsmith Mp4v2
APPTechsmith2.0.0
Related vulnerabilities
MP4v2: type confusion w MP4NameFirstMatches prowadząca do out-of-bounds memory access
Double free w klasie MP4StringProperty biblioteki MP4v2 2.0.0
MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of servic...
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4at...
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the...