The AP4_AtomSampleTable::GetSample function in Core/Ap4AtomSampleTable.cpp in Bento4 mp42ts before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bento4 | Bento4 | * | 1.5.0-615 (including) |
Kodi-inputstream-adaptive | Ubuntu | kinetic | * |
Kodi-inputstream-adaptive | Ubuntu | lunar | * |
Kodi-inputstream-adaptive | Ubuntu | mantic | * |
Kodi-inputstream-adaptive | Ubuntu | oracular | * |
Kodi-inputstream-adaptive | Ubuntu | trusty | * |
Kodi-inputstream-adaptive | Ubuntu | xenial | * |