PT-2019-15307 · Videolan+1 · Vlc Media Player+1

Code16

·

Published

2019-10-23

·

Updated

2020-08-24

·

CVE-2019-18278

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VideoLAN VLC media player version 3.0.8
Description The issue occurs when executing VideoLAN VLC media player 3.0.8 with libqt on Windows. Data from a faulting address controls code flow, starting at a specific location within the libqt plugin. The VideoLAN security team has not been contacted about this issue and is unable to reproduce it.
Recommendations For version 3.0.8, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-18278

Affected Products

Vlc Media Player
Libqt