CVE-2019-20091: Null Pointer Dereference
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4Descriptor::GetTag in mp42ts when called from AP4DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20091?
CVE-2019-20091 has been classified as a medium severity vulnerability due to the potential for causing crashes in the affected software.
How do I fix CVE-2019-20091?
To fix CVE-2019-20091, upgrade to a later version of Bento4 that addresses this NULL pointer dereference issue.
What software versions are affected by CVE-2019-20091?
CVE-2019-20091 affects Bento4 version 1.5.1.0 and potentially earlier versions.
What is the impact of CVE-2019-20091?
CVE-2019-20091 could lead to application crashes or denial of service when processing specific media files.
Where can I find more information about CVE-2019-20091?
For more information on CVE-2019-20091, you can check the issue tracker on the Bento4 GitHub repository.