A NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.
{
"cpe": "cpe:2.3:a:bento4:bento4:1.5.0-617:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.5.0-617"
},
{
"last_affected": "1.5.0-617"
}
],
"source": [
"CPE_STRING",
"REFERENCES"
]
}[
{
"target": {
"file": "Source/C++/Core/Ap4AtomSampleTable.cpp"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"308572507585856352145932927881347175705",
"272557305027728360472162646032749043289",
"165323675687539707753772975874818096364",
"285021036354712794539596122825774242153",
"166594828238651843661541181788043470174"
],
"threshold": 0.9
},
"id": "CVE-2017-14640-645afdad",
"source": "https://github.com/axiomatic-systems/bento4/commit/2f267f89f957088197f4b1fc254632d1645b415d"
},
{
"target": {
"function": "AP4_AtomSampleTable::GetSample",
"file": "Source/C++/Core/Ap4AtomSampleTable.cpp"
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"function_hash": "19319967281882059049951904879574726754",
"length": 1856.0
},
"id": "CVE-2017-14640-945069a4",
"source": "https://github.com/axiomatic-systems/bento4/commit/2f267f89f957088197f4b1fc254632d1645b415d"
}
]
"2026-07-08T15:10:36Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14640.json"