An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Test component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Bento4 | Axiosys | * | 1.6.0-636 (including) | 
| Kodi-inputstream-adaptive | Ubuntu | kinetic | * | 
| Kodi-inputstream-adaptive | Ubuntu | lunar | * | 
| Kodi-inputstream-adaptive | Ubuntu | mantic | * | 
| Kodi-inputstream-adaptive | Ubuntu | oracular | * | 
| Kodi-inputstream-adaptive | Ubuntu | trusty | * | 
| Kodi-inputstream-adaptive | Ubuntu | xenial | * |