CVE-2019-17453: Null Pointer Dereference
Published Oct 10, 2019
·Updated
Bento4 1.5.1.0 has a NULL pointer dereference in AP4DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact.
Affected Software
1 affected component
Axiosys Bento4=1.5.1.0
Event History
Oct 10, 2019
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17453?
CVE-2019-17453 is categorized as a medium severity vulnerability due to its potential to cause application instability.
2
How do I fix CVE-2019-17453?
To fix CVE-2019-17453, users should upgrade to a patched version of Bento4 that addresses this NULL pointer dereference issue.
3
What software is affected by CVE-2019-17453?
The affected software for CVE-2019-17453 is Bento4 version 1.5.1.0.
4
What kind of vulnerability is CVE-2019-17453?
CVE-2019-17453 is a NULL pointer dereference vulnerability that can lead to application crashes.
5
How can I check if my Bento4 installation is vulnerable to CVE-2019-17453?
You can check if your Bento4 installation is vulnerable by verifying that you are using version 1.5.1.0.