CVE-2022-3809

Name
CVE-2022-3809
Description
A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212666 is the identifier assigned to this vulnerability.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/axiomatic-systems/Bento4/issues/779
MISC https://vuldb.com/?id.212666
MISC https://github.com/axiomatic-systems/Bento4/files/9653209/poc_Bento4.zip

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:axiosys:bento4:*:*:*:*:*:*:*:* bento4 >= None <= 1.6.0-639

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
bento4 3.17-community 1.6.0.639-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
bento4 3.18-community 1.6.0.640-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
bento4 edge-community 1.6.0.641-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
bento4 3.19-community 1.6.0.641-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable
bento4 3.20-community 1.6.0.641-r0 Patrycja Rosa <alpine@ptrcnull.me> possibly vulnerable