First published: Mon Dec 30 2019(Updated: )
An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bento4 | =1.5.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20090 is classified as a medium severity vulnerability due to its potential for exploitation.
To fix CVE-2019-20090, you should update Bento4 to the latest version that addresses this use-after-free vulnerability.
The use-after-free vulnerability in CVE-2019-20090 affects the sample offset retrieval function in Bento4.
CVE-2019-20090 specifically affects Bento4 version 1.5.1.0, so it should be evaluated against other versions.
CVE-2019-20090 can be exploited by an attacker who can control the input to the affected function in the Bento4 software.