CVE Vulnerabilities

CVE-2023-48727

Use of NullPointerException Catch to Detect NULL Pointer Dereference

Published: May 16, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW

NULL pointer dereference in some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable information disclosure via local access.

Weakness

Catching NullPointerException should not be used as an alternative to programmatic checks to prevent dereferencing a null pointer.

Affected Software

Name Vendor Start Version End Version
Onevpl Ubuntu devel *
Onevpl Ubuntu esm-apps/jammy *
Onevpl Ubuntu esm-apps/noble *
Onevpl Ubuntu jammy *
Onevpl Ubuntu noble *
Onevpl Ubuntu oracular *
Onevpl Ubuntu upstream *

Extended Description

Programmers typically catch NullPointerException under three circumstances:

Of these three circumstances, only the last is acceptable.

Potential Mitigations

References