Related Vulnerabilities: CVE-2018-14403  

MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.

Severity High

Remote No

Type Information disclosure

Description

MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.

AVG-848 libmp4v2 2.0.0-5 4.1.3-1 High Testing

https://www.openwall.com/lists/oss-security/2018/07/18/3