CVE-2019-20090: Use After Free
Published Dec 30, 2019
·Updated
An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.
Affected Software
1 affected component
Axiosys Bento4=1.5.1.0
Event History
Dec 30, 2019
CVE Published
via MITRE·03:48 AM
Data Sourced
via MITRE·03:48 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20090?
CVE-2019-20090 is classified as a medium severity vulnerability due to its potential for exploitation.
2
How do I fix CVE-2019-20090?
To fix CVE-2019-20090, you should update Bento4 to the latest version that addresses this use-after-free vulnerability.
3
What does the use-after-free vulnerability in CVE-2019-20090 affect?
The use-after-free vulnerability in CVE-2019-20090 affects the sample offset retrieval function in Bento4.
4
Is CVE-2019-20090 present in other Bento4 versions?
CVE-2019-20090 specifically affects Bento4 version 1.5.1.0, so it should be evaluated against other versions.
5
How can CVE-2019-20090 be exploited?
CVE-2019-20090 can be exploited by an attacker who can control the input to the affected function in the Bento4 software.