CVE-2019-17452: Null Pointer Dereference
Published Oct 10, 2019
·Updated
Bento4 1.5.1.0 has a NULL pointer dereference in AP4DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump.
Affected Software
1 affected component
Axiosys Bento4=1.5.1.0
Event History
Oct 10, 2019
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17452?
CVE-2019-17452 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2019-17452?
To fix CVE-2019-17452, it is recommended to update Bento4 to a version that is patched for this vulnerability.
3
What is the impact of CVE-2019-17452?
The impact of CVE-2019-17452 includes potential application crashes due to a NULL pointer dereference.
4
Which software versions are affected by CVE-2019-17452?
CVE-2019-17452 affects Bento4 version 1.5.1.0.
5
Can CVE-2019-17452 be exploited remotely?
Yes, CVE-2019-17452 can potentially be exploited remotely through crafted MP4 files.