CVE Vulnerabilities

CVE-2019-20167

NULL Pointer Dereference

Published: Dec 31, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function senc_Parse() in isomedia/box_code_drm.c.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Gpac Gpac 0.8.0 (including) 0.8.0 (including)
Gpac Gpac 0.9.0 (including) 0.9.0 (including)
Gpac Ubuntu bionic *
Gpac Ubuntu disco *
Gpac Ubuntu eoan *
Gpac Ubuntu focal *
Gpac Ubuntu groovy *
Gpac Ubuntu hirsute *
Gpac Ubuntu impish *
Gpac Ubuntu kinetic *
Gpac Ubuntu lunar *
Gpac Ubuntu trusty *
Gpac Ubuntu trusty/esm *
Gpac Ubuntu xenial *

Potential Mitigations

References