Axiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resources

CVE Details

Basic Information

Title Axiomatic Bento4 mp4decrypt Mp4Decrypt.cpp SetDataSize allocation of resources
Type cve
Published 2025-08-05T00:32:06.097Z
Modified 2025-08-05T00:32:06.097Z

Product Information

Vendor Axiomatic
Product Bento4
Version 1.6.0-641

CVSS Information

Base Score 6.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A vulnerability in Axiomatic Bento4’s mp4decrypt component allows remote attackers to cause resource allocation issues, though exploitation is complex and difficult.
AI Severity Medium
AI Vendor Axiomatic
AI Product Bento4
AI Version 1.6.0-641

Affected Products

  • Axiomatic Bento4 1.6.0-641

Additional Information

CWE List CWE-770, CWE-400
Source VulDB

Description

A vulnerability, which was classified as problematic, was found in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_DataBuffer::SetDataSize of the file Mp4Decrypt.cpp of the component mp4decrypt. The manipulation leads to allocation of resources. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.