CVE-2025-25947

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 19, 2025
Updated: Feb 20, 2025
CWE ID 665

Summary

CVE-2025-25947 is a vulnerability affecting Bento4 version 1.6.0-641. This issue permits an attacker to induce a segmentation fault in Ap4Atom.cpp, particularly within the AP4_AtomParent::RemoveChild function. The flaw can be exploited through a maliciously crafted MP4 input file during the processing of mp4encrypt. Successful exploitation may lead to application crashes or potential memory disclosures. It is essential to update Bento4 to a patched version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share