CVE-2024-57510 Details
Description
Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial.
A buffer overflow vulnerability has been identified in Bento4's mp42avc application, specifically in the commit related to this issue. This vulnerability allows a local attacker to execute arbitrary code by exploiting the AP4_MemoryByteStream::WritePartial function. The issue arises from improper handling of data, leading to memory corruption that can be manipulated to execute malicious code.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 29, 2025CISA-ADP
Assessed Feb 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/axiomatic-systems/Bento4/issues/989 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gist.github.com/G2FUZZ/91a1cc3b8f2b0720e984353d59023b24 | [email protected] | BundleTechnical Description |
| https://github.com/axiomatic-systems/Bento4/issues/989 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Bento4 mp42avc | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2025 | CVE Modified | CISA-ADP |
| Jan 29, 2025 | New CVE Received | [email protected] |
Volerion