LiveActive security incident?Get immediate response
CVE Record

CVE-2017-14638: AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NU...

AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL pointer dereference, segmentation fault, and application crash in AP4_Atom::SetType in Core/Ap4Atom.h.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Bento4 1.5.0-617 can crash while processing malformed media data because a missing NULL check reaches AP4_Atom::SetType. The known impact is application availability, not data theft or code execution. Business urgency depends on whether Bento4 parses untrusted media in production workflows.

Executive priority

Treat this as a targeted availability risk. It should be prioritized for media ingestion, transcoding, scanning, or file-upload services, but it is not supported by the sources as an active exploitation or data breach emergency.

Technical view

The CVE describes a NULL pointer dereference in AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp, leading to a segmentation fault in AP4_Atom::SetType in Core/Ap4Atom.h. The source bundle identifies Bento4 version 1.5.0-617 and references a GitHub issue, Gentoo report, and upstream commit.

Likely exposure

Exposure is most likely where Bento4 1.5.0-617, or software embedding it, parses user-supplied or externally sourced media files. The source bundle does not identify downstream products, packages, or environments beyond Bento4.

Exploitation context

The sources support a crash condition from malformed input, but do not show active exploitation, KEV listing, code execution, privilege escalation, or data compromise. KEV is false in the supplied bundle.

Researcher notes

Evidence is limited to public CVE metadata, a Gentoo report, a GitHub issue, and an upstream commit reference. The supplied data lacks CVSS, CWE, exploit status, affected downstream products, and exact fixed release information.

Mitigation direction

  • Identify Bento4 usage and embedded copies in media-processing workflows.
  • Check vendor or upstream guidance for a release containing the referenced fix commit.
  • Prioritize systems that parse untrusted media from users or partners.
  • Isolate media parsing so crashes do not affect critical services.

Validation and detection

  • Inventory Bento4 versions and confirm whether 1.5.0-617 is present.
  • Review SBOMs and vendor components for bundled Bento4 code.
  • Confirm whether services accept untrusted media input.
  • Verify deployed builds include the referenced upstream fix or later vendor guidance.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-14638 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.