Axiomatic Systems · Bento4 · CVE-2019-20091
**Name of the Vulnerable Software and Affected Versions**
Bento4 version 1.5.1.0
**Description**
A NULL pointer dereference issue was discovered in the `AP4 Descriptor::GetTag` function when called from `AP4 DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor` in Ap4DecoderConfigDescriptor.cpp, potentially leading to a crash or other unintended behavior.
**Recommendations**
For Bento4 version 1.5.1.0, at the moment, there is no information about a newer version that contains a fix for this issue.