There exists one NULL pointer dereference vulnerability in AP4_JsonInspector::AddField in Ap4Atom.cpp in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp4dump.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bento4 | Axiosys | 1.5.1-624 (including) | 1.5.1-624 (including) |
Kodi-inputstream-adaptive | Ubuntu | kinetic | * |
Kodi-inputstream-adaptive | Ubuntu | lunar | * |
Kodi-inputstream-adaptive | Ubuntu | mantic | * |
Kodi-inputstream-adaptive | Ubuntu | oracular | * |
Kodi-inputstream-adaptive | Ubuntu | trusty | * |
Kodi-inputstream-adaptive | Ubuntu | xenial | * |