PT-2019-2909 · Videolan+3 · Vlc Media Player+3

Publicado

2019-06-27

·

Atualizado

2024-06-15

·

CVE-2019-13602

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VLC media player versions prior to 3.0.7.1
Description The issue is related to an integer underflow in the MP4 EIA608 Convert() function, located in modules/demux/mp4/mp4.c, which leads to a heap-based buffer overflow. This can be exploited by a remote attacker to cause a denial of service or potentially have other unspecified impacts by using a crafted .mp4 file.
Recommendations For versions prior to 3.0.7.1, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider avoiding the use of the MP4 EIA608 Convert() function until a patch is available.

Correção

DoS

Integer Underflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2483
ALT-PU-2019-2509
BDU:2019-02879
CVE-2019-13602
DSA-4504-1
MGASA-2019-0233
OPENSUSE-SU-2019:1840-1
OPENSUSE-SU-2019:1897-1
OPENSUSE-SU-2019:1909-1
OPENSUSE-SU-2019:2015-1
OPENSUSE-SU-2019_1840-1
OPENSUSE-SU-2019_1909-1
OPENSUSE-SU-2020:0545-1
OPENSUSE-SU-2020:0562-1
OPENSUSE-SU-2020_0545-1
OPENSUSE-SU-2024:11502-1
USN-4074-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Vlc Media Player