CVE-2019-13238: Null Pointer Dereference
An issue was discovered in Bento4 1.5.1.0. A memory allocation failure is unhandled in Core/Ap4SdpAtom.cpp and leads to crashes. When parsing input video, the program allocates a new buffer to parse an atom in the stream. The unhandled memory allocation failure causes a direct copy to a NULL pointer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13238?
CVE-2019-13238 is a vulnerability discovered in Bento4 version 1.5.1.0 that allows for memory allocation failures in the program, leading to crashes.
How severe is CVE-2019-13238?
CVE-2019-13238 has a severity rating of 7.5 out of 10, indicating a high severity.
How does CVE-2019-13238 affect Axiosys Bento4?
CVE-2019-13238 affects Axiosys Bento4 version 1.5.1.0, causing memory allocation failures that can lead to crashes.
Is there a fix for CVE-2019-13238?
At this time, there is no known fix for CVE-2019-13238. It is recommended to update to a newer version of Bento4 if available or to apply any patches or fixes provided by the vendor.
Where can I find more information about CVE-2019-13238?
You can find more information about CVE-2019-13238 on the GitHub link provided: https://github.com/axiomatic-systems/Bento4/issues/396