CVE-2019-17539: Null Pointer Dereference
In FFmpeg before 4.2, avcodecopen2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-17539?
CVE-2019-17539 is a vulnerability in FFmpeg before 4.2 that allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
What is the severity of CVE-2019-17539?
CVE-2019-17539 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2019-17539?
The affected software versions include FFmpeg versions up to 4.0.5, 4.1.5, and 3.4.7, as well as Debian Linux 9.0, Debian Linux 10.0, and Canonical Ubuntu Linux 16.04, 18.04, and 20.04.
How do I fix CVE-2019-17539?
To fix CVE-2019-17539, update to FFmpeg version 4.2 or higher and apply the available patches provided by your operating system vendor.
Where can I find more information about CVE-2019-17539?
You can find more information about CVE-2019-17539 on the CVE Mitre website, the Chromium OSS-Fuzz bug tracker, and the Ubuntu Security Notices website.