CVE-2022-3666

Source
https://cve.org/CVERecord?id=CVE-2022-3666
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-3666.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-3666
Downstream
Published
2022-10-26T00:00:00Z
Modified
2026-07-15T01:48:50.670026116Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Axiomatic Bento4 mp42ts Ap4LinearReader.cpp Advance use after free
Details

A vulnerability, which was classified as critical, has been found in Axiomatic Bento4. Affected by this issue is the function AP4_LinearReader::Advance of the file Ap4LinearReader.cpp of the component mp42ts. The manipulation leads to use after free. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212006 is the identifier assigned to this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-119"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/3xxx/CVE-2022-3666.json"
}
References

Affected packages

Git / github.com/axiomatic-systems/bento4

Affected ranges

Type
GIT
Repo
https://github.com/axiomatic-systems/bento4
Events
Database specific
{
    "cpe": "cpe:2.3:a:axiosys:bento4:1.6.0-639:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.6.0-639"
        },
        {
            "last_affected": "1.6.0-639"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.6.0-639
v1.*
v1.6.0-639

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-3666.json"