CVE-2018-19937: Medium severity vlc media player vulnerability
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-19937?
CVE-2018-19937 is a vulnerability in the VideoLAN VLC media player app for iOS that allows a local authenticated attacker to bypass the passcode by opening a URL and turning the phone.
How can an attacker exploit CVE-2018-19937?
An attacker with local authentication can exploit CVE-2018-19937 by opening a URL and turning the phone to bypass the passcode in the VLC media player app for iOS.
What is the severity level of CVE-2018-19937?
CVE-2018-19937 has a severity level of medium with a CVSS score of 6.6.
Which version of the VideoLAN VLC media player app for iOS is affected by CVE-2018-19937?
CVE-2018-19937 affects versions of the VideoLAN VLC media player app for iOS before 3.1.5.
Is there a fix available for CVE-2018-19937?
Yes, upgrading to version 3.1.5 of the VideoLAN VLC media player app for iOS will fix CVE-2018-19937.