VDB
CVE-2018-14403
CVE-2018-14403
PUBLISHED
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access.
EPSS 0.45% · 63.9th percentile
Risk Scores
EPSS Score
0.45%
63.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | mp4v2 | 0, 2.0.0~dfsg0-6 |
| Ubuntu:16.04:LTS | mp4v2 | 0, 2.0.0~dfsg0-3, * |
Exploit Intelligence
Timeline
- Jul 19, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-14403 third-party-advisory
- http://www.openwall.com/lists/oss-security/2018/07/18/3 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-14403 third-party-advisory