CVE-2023-33718
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 401
Summary
CVE-2023-33718 is a newly disclosed vulnerability affecting version 2.1.3 of the mp4v2 library. The issue stems from a memory leak in the MP4File::ReadString() function located at mp4file_io.cpp. An attacker can exploit this vulnerability by manipulating MP4 files in a way that causes the library to leak memory, potentially leading to a denial-of-service condition or, in some cases, arbitrary code execution. Developers are urged to update to the latest version of mp4v2 to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.