NULL pointer dereference in some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable information disclosure via local access.
{
"binaries": [
{
"binary_name": "libvpl-dev",
"binary_version": "2023.3.0-1build1"
},
{
"binary_name": "libvpl2",
"binary_version": "2023.3.0-1build1"
},
{
"binary_name": "onevpl-tools",
"binary_version": "2023.3.0-1build1"
}
],
"priority_reason": "This is rated low severity by Intel"
}