CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-25947: An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild,...

Description

An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.

Classification

CVE ID: CVE-2025-25947

Affected Products

Vendor: n/a

Product: n/a

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 1.66% (scored less or equal to compared to others)

EPSS Date: 2025-03-20 (when was this score calculated)

References

https://github.com/axiomatic-systems/Bento4/issues/994

Timeline