CVE-2019-8382: Null Pointer Dereference
An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4List:Find located in Core/Ap4List.h when called from Core/Ap4Movie.cpp. It can be triggered by sending a crafted file to the mp4dump binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8382?
CVE-2019-8382 has a critical severity level due to the potential for Denial of Service attacks.
How do I fix CVE-2019-8382?
To fix CVE-2019-8382, update Bento4 to a patched version or apply available security patches.
What types of attacks can CVE-2019-8382 facilitate?
CVE-2019-8382 can facilitate Denial of Service attacks by causing a NULL pointer dereference.
Which software versions are affected by CVE-2019-8382?
CVE-2019-8382 affects Bento4 version 1.5.1-628.
What component of Bento4 is impacted by CVE-2019-8382?
CVE-2019-8382 impacts the AP4_List:Find function located in Core/Ap4List.h.