First published: Wed Mar 13 2019(Updated: )
In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a similar issue to CVE-2018-19212.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmproject Libwebm | <=1.0.0.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9746 is a vulnerability found in libwebm before 2019-03-08 that can lead to a denial-of-service (DoS) attack by triggering a NULL pointer dereference.
CVE-2019-9746 can be exploited by calling the OutputCluster or OutputTracks functions in webm_info.cc with a NULL pointer, causing an abort and resulting in a DoS attack.
The severity of CVE-2019-9746 is high, with a CVSS score of 7.5.
The affected software is Webmproject Libwebm version 1.0.0.27.
To fix CVE-2019-9746, update to a version of libwebm after 2019-03-08 that includes the necessary patch to address the NULL pointer dereference.