PT-2021-7906 · Aom+4 · Aom+4

Published

2021-12-02

·

Updated

2024-01-31

·

CVE-2020-36130

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions AOM version 2.0.1
Description The issue is related to a NULL pointer dereference in the av1/av1 dx iface.c component of the AOM library, which implements the AV1 codec. This could allow a remote attacker to cause a denial of service. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For AOM version 2.0.1, consider applying a patch or fix to resolve the NULL pointer dereference issue in the av1/av1 dx iface.c component. As a temporary workaround, consider restricting access to the vulnerable component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2023-05293
CVE-2020-36130
DLA-3556-1
DSA-5490-1
MGASA-2022-0040
OPENSUSE-SU-2021:1624-1
OPENSUSE-SU-2021:4170-1
OPENSUSE-SU-2021_1624-1
OPENSUSE-SU-2021_4170-1
SUSE-SU-2021:4170-1
USN-6447-1

Affected Products

Aom
Astra Linux
Linuxmint
Suse
Ubuntu