CVE-2023-33717

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jun 2, 2023
Updated: Jan 8, 2025
CWE ID 401

Summary

CVE-2023-33717 is a memory leak vulnerability affecting mp4v2 version 2.1.3. During the use of the MP4File::ReadBytes() method, the software fails to properly handle exceptions, resulting in memory that is allocated but not released. This issue can lead to excessive memory usage and potential denial-of-service attacks if exploited. It is recommended that users of mp4v2 upgrade to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share