CVE-2025-0870

Source
https://cve.org/CVERecord?id=CVE-2025-0870
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0870.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-0870
Published
2025-01-30T13:15:10.483Z
Modified
2026-04-10T05:20:21.439263Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::GetData in the library Ap4DataBuffer.h. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

References

Affected packages

Git / github.com/axiomatic-systems/bento4

Affected ranges

Type
GIT
Repo
https://github.com/axiomatic-systems/bento4
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.6.0-641"
        }
    ]
}

Affected versions

v1.*
v1.4.2-584
v1.4.2-586
v1.4.2-587
v1.4.2-588
v1.4.2-589
v1.4.2-590
v1.4.2-591
v1.4.2-592
v1.4.2-593
v1.4.2-594
v1.4.3-595
v1.4.3-596
v1.4.3-597
v1.4.3-598
v1.4.3-599
v1.4.3-600
v1.4.3-601
v1.4.3-602
v1.4.3-603
v1.4.3-604
v1.4.3-605
v1.4.3-606
v1.4.3-607
v1.4.3-608
v1.5.0-609
v1.5.0-610
v1.5.0-611
v1.5.0-612
v1.5.0-613
v1.5.0-615
v1.5.0-616
v1.5.0-617
v1.5.0-618
v1.5.0-619
v1.5.1-620
v1.5.1-621
v1.5.1-622
v1.5.1-623
v1.5.1-624
v1.5.1-626
v1.5.1-629
v1.5.1-630
v1.6.0-635
v1.6.0-636
v1.6.0-637
v1.6.0-638
v1.6.0-639
v1.6.0-640
v1.6.0-641

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0870.json"