#VU34930 NULL pointer dereference in Bento4 - CVE-2019-20091
Published: December 30, 2019 / Updated: August 8, 2020
Bento4
axiomatic-systems
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp. A remote attacker can perform a denial of service (DoS) attack.