CVE-2018-7339 Information
Feb 14, 2021
cve
Description
The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property which allows remote attackers to cause a denial of service (overflow insufficient memory allocation and segmentation fault) or possibly have unspecified other impact via a crafted mp4 file.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://github.com/pingsuewim/libmp4_bof
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: