CVE Vulnerabilities

CVE-2018-5253

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 05, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
Bento4Axiosys1.5.1.0 (including)1.5.1.0 (including)
Kodi-inputstream-adaptiveUbuntukinetic*
Kodi-inputstream-adaptiveUbuntulunar*
Kodi-inputstream-adaptiveUbuntumantic*
Kodi-inputstream-adaptiveUbuntuoracular*
Kodi-inputstream-adaptiveUbuntuplucky*
Kodi-inputstream-adaptiveUbuntutrusty*
Kodi-inputstream-adaptiveUbuntuxenial*

References