CVE-2022-3809

MEDIUM

Bento4 < 1.6.0-639 - Denial of Service in mp4tag ParseCommandLine

Title source: llm
STIX 2.1

Description

A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function ParseCommandLine of the file Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212666 is the identifier assigned to this vulnerability.

References (3)

Core 3
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/axiomatic-systems/Bento4/issues/779
Permissions Required, Third Party Advisory
https://vuldb.com/?id.212666

Scores

CVSS v3 4.3
EPSS 0.0079
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (1)
axiosys/bento4 < 1.6.0-639
Published Nov 02, 2022
Tracked Since Feb 18, 2026