ZeroHour

CVE-2018-14403

PoC
CVSS 3.0
9.8 critical
EPSS
3%p84
Published
()
Modified
Description

MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.

Vendors
techsmith
Products
mp4v2
Weakness
CWE-704
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.