In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as demonstrated by GPAC. This can cause a denial of service (DOS).
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Bento4 | Axiosys | 1.6.0-638 (including) | 1.6.0-638 (including) | 
| Kodi-inputstream-adaptive | Ubuntu | kinetic | * | 
| Kodi-inputstream-adaptive | Ubuntu | lunar | * | 
| Kodi-inputstream-adaptive | Ubuntu | mantic | * | 
| Kodi-inputstream-adaptive | Ubuntu | oracular | * | 
| Kodi-inputstream-adaptive | Ubuntu | trusty | * | 
| Kodi-inputstream-adaptive | Ubuntu | xenial | * |