CVE-2019-20166: Null Pointer Dereference
Published Dec 30, 2019
·Updated
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gfisomdump() in isomedia/boxdump.c.
Affected Software
2 affected components
Gpac GPAC=0.8.0
Gpac GPAC=0.9.0
Event History
Dec 30, 2019
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20166?
CVE-2019-20166 is classified as a moderate severity vulnerability due to the potential for application crashes.
2
How do I fix CVE-2019-20166?
To fix CVE-2019-20166, upgrade to a version of GPAC later than 0.9.0 that addresses this issue.
3
What impact does CVE-2019-20166 have on systems running GPAC?
CVE-2019-20166 may lead to a NULL pointer dereference, resulting in application instability or crashes.
4
Which versions of GPAC are affected by CVE-2019-20166?
Versions 0.8.0 and 0.9.0-development-20191109 of GPAC are affected by CVE-2019-20166.
5
Is there a workaround for CVE-2019-20166 in affected GPAC versions?
There are no officially recommended workarounds for CVE-2019-20166; upgrading to a fixed version is advised.