CVE Vulnerabilities

CVE-2018-14403

Incorrect Type Conversion or Cast

Published: Jul 19, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

NameVendorStart VersionEnd Version
Mp4v2Techsmith2.0.0 (including)2.0.0 (including)
Mp4v2Ubuntuartful*
Mp4v2Ubuntubionic*
Mp4v2Ubuntucosmic*
Mp4v2Ubuntuesm-apps/bionic*
Mp4v2Ubuntuesm-apps/xenial*
Mp4v2Ubuntutrusty*
Mp4v2Ubuntuupstream*
Mp4v2Ubuntuxenial*

References