A double free exists in the MP4StringProperty class in mp4property.cpp in MP4v2 2.0.0. A dangling pointer is freed again in the destructor once an exception is triggered. References: http://www.openwall.com/lists/oss-security/2018/07/13/1
Created libmp4v2 tracking bugs for this issue: Affects: epel-all [bug 1603298] Affects: fedora-all [bug 1603296]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.