CVE-2019-9746

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
13/03/2019
Last modified:
14/03/2019

Description

In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_info.cc will trigger an abort, which allows a DoS attack, a similar issue to CVE-2018-19212.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webmproject:libwebm:*:*:*:*:*:*:*:* 1.0.0.27 (including)