First published: Thu Jul 18 2019(Updated: )
In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1-627 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13959 is rated as a high severity vulnerability due to the potential for a memory copy into a NULL pointer, which may lead to application instability.
To fix CVE-2019-13959, update to a newer version of Bento4 where the reallocation failure handling has been resolved.
CVE-2019-13959 represents a memory management issue in Bento4's AP4_DataBuffer class that fails to handle reallocation errors.
CVE-2019-13959 affects Bento4 version 1.5.1-627.
Yes, CVE-2019-13959 is a different issue from CVE-2018-20186, despite both being related to memory handling in Bento4.