CVE Vulnerabilities

CVE-2018-14054

Double Free

Published: Jul 13, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again in the destructor once an exception is triggered.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Mp4v2Techsmith2.0.0 (including)2.0.0 (including)
Mp4v2Ubuntuartful*
Mp4v2Ubuntubionic*
Mp4v2Ubuntucosmic*
Mp4v2Ubuntuesm-apps/bionic*
Mp4v2Ubuntuesm-apps/xenial*
Mp4v2Ubuntutrusty*
Mp4v2Ubuntuupstream*
Mp4v2Ubuntuxenial*

Potential Mitigations

References