First published: Thu Dec 02 2021(Updated: )
AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component av1/av1_dx_iface.c.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aomedia Aomedia | =2.0.1 | |
ubuntu/aom | <1.0.0. | 1.0.0. |
ubuntu/aom | <3.2.0-1 | 3.2.0-1 |
debian/aom | 1.0.0.errata1-3+deb11u1 3.6.0-1 3.9.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-36130 is medium with a CVSS score of 6.5.
CVE-2020-36130 affects AOM v2.0.1 by causing a NULL pointer dereference in the av1/av1_dx_iface.c component.
CVE-2020-36130 affects AOM v2.0.1, Debian's aom version 1.0.0-3+deb10u1, 1.0.0.errata1-3+deb11u1, 3.6.0-1, and 3.7.0-1, as well as Ubuntu's aom version 3.2.0-1 and aom version 1.0.0.* with qualifier 'focal'.
To fix CVE-2020-36130 in AOM v2.0.1, update to a newer version of AOM that does not contain the NULL pointer dereference vulnerability.
You can find more information about CVE-2020-36130 in the references provided: [here](https://bugs.chromium.org/p/aomedia/issues/detail?id=2905&q=&can=1), [here](https://lists.debian.org/debian-lts-announce/2023/09/msg00003.html), and [here](https://www.debian.org/security/2023/dsa-5490).