PT-2019-2909 · Videolan+3 · Vlc Media Player+3

Published

2019-06-27

·

Updated

2024-06-15

·

CVE-2019-13602

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VLC media player versions prior to 3.0.7.1
Description The issue is related to an integer underflow in the MP4 EIA608 Convert() function, located in modules/demux/mp4/mp4.c, which leads to a heap-based buffer overflow. This can be exploited by a remote attacker to cause a denial of service or potentially have other unspecified impacts by using a crafted .mp4 file.
Recommendations For versions prior to 3.0.7.1, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider avoiding the use of the MP4 EIA608 Convert() function until a patch is available.

Fix

DoS

Integer Underflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2483
ALT-PU-2019-2509
BDU:2019-02879
CVE-2019-13602
DSA-4504-1
MGASA-2019-0233
OPENSUSE-SU-2019:1840-1
OPENSUSE-SU-2019:1897-1
OPENSUSE-SU-2019:1909-1
OPENSUSE-SU-2019:2015-1
OPENSUSE-SU-2019_1840-1
OPENSUSE-SU-2019_1909-1
OPENSUSE-SU-2020:0545-1
OPENSUSE-SU-2020:0562-1
OPENSUSE-SU-2020_0545-1
OPENSUSE-SU-2024:11502-1
USN-4074-1

Affected Products

Alt Linux
Suse
Ubuntu
Vlc Media Player