SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14403

The resulting type confusion can cause out-of-bounds memory access.

CRITICAL 9.8EPSS 2.60%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.60% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-704
Affected
techsmith/mp4v2
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.