In Bento4 1.5.1-627, AP4_DataBuffer::SetDataSize does not handle reallocation failures, leading to a memory copy into a NULL pointer. This is different from CVE-2018-20186.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Bento4 | Axiosys | 1.5.1-627 (including) | 1.5.1-627 (including) | 
| Kodi-inputstream-adaptive | Ubuntu | kinetic | * | 
| Kodi-inputstream-adaptive | Ubuntu | lunar | * | 
| Kodi-inputstream-adaptive | Ubuntu | mantic | * | 
| Kodi-inputstream-adaptive | Ubuntu | oracular | * | 
| Kodi-inputstream-adaptive | Ubuntu | trusty | * | 
| Kodi-inputstream-adaptive | Ubuntu | xenial | * |