CVE-2019-20165: Null Pointer Dereference
Published Dec 30, 2019
·Updated
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilstitemRead() in isomedia/boxcodeapple.c.
Affected Software
3 affected components
Gpac GPAC=0.8.0
Gpac GPAC=0.9.0
Debian Debian Linux=8.0
Event History
Dec 30, 2019
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20165?
CVE-2019-20165 has not been assigned a specific severity rating but involves a NULL pointer dereference that can lead to application crashes.
2
How do I fix CVE-2019-20165?
To fix CVE-2019-20165, upgrade GPAC to a version beyond 0.9.0 that addresses this vulnerability.
3
Which versions of GPAC are affected by CVE-2019-20165?
CVE-2019-20165 affects GPAC versions 0.8.0 and 0.9.0-development-20191109.
4
Is CVE-2019-20165 exploitable remotely?
CVE-2019-20165 is not specifically described as remotely exploitable but could be triggered through manipulating input files.
5
What component of GPAC is vulnerable in CVE-2019-20165?
The vulnerability in CVE-2019-20165 is present in the ilst_item_Read() function located in isomedia/box_code_apple.c.