CVE-2019-20092: Null Pointer Dereference
Published Dec 30, 2019
·Updated
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4Descriptor::GetTag in mp42ts when called from AP4EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp.
Affected Software
1 affected component
Axiosys Bento4=1.5.1.0
Event History
Dec 30, 2019
CVE Published
via MITRE·03:48 AM
Data Sourced
via MITRE·03:48 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20092?
CVE-2019-20092 is classified as having a medium severity due to its potential for causing application crashes.
2
How do I fix CVE-2019-20092?
To fix CVE-2019-20092, upgrade to the latest version of Bento4 that includes the patch for this vulnerability.
3
What software is affected by CVE-2019-20092?
CVE-2019-20092 affects Bento4 version 1.5.1.0.
4
What type of vulnerability is CVE-2019-20092?
CVE-2019-20092 is a NULL pointer dereference vulnerability.
5
What is the impact of CVE-2019-20092?
The impact of CVE-2019-20092 can lead to application crashes when processing certain media files.