Skip to content

Instantly share code, notes, and snippets.

1. CVE-2024-57509
(a) Suggested description: Buffer Overflow vulnerability in Bento4 mp42avc. Allow a local attacker to execute arbitrary code via the AP4_File::ParseStream and related functions
(b) Vulnerability Type: Buffer Overflow
(c) Vendor of Product: Bento4
(d) Affected Product Code Base: Affected product: mp42avc. The related commit of Bento4 is 3bdc891602d19789b8e8626e4a3e613a937b4d35
(e) Attack Type: Local
(f) Attack Vectors: Details can be seen in https: https://github.com/axiomatic-systems/Bento4/issues/989
2. CVE-2024-57510
(a) Suggested description: Buffer Overflow vulnerability in Bento4 mp42avc. Allow a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial