CVE-2023-33720

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published May 26, 2023
Updated: Jan 14, 2025
CWE ID 400
CWE ID 770

Summary

CVE-2023-33720 is a newly disclosed memory leak vulnerability affecting version 2.1.2 of the mp4v2 library. The issue arises from a defect within the MP4BytesProperty class, which could potentially lead to memory exhaustion and cause the application to crash or even allow an attacker to execute arbitrary code. An attacker could exploit this vulnerability by manipulating specially crafted MP4 files to trigger the memory leak. This vulnerability poses a significant risk to organizations using this library in their multimedia applications and requires immediate patching to mitigate potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share