First published: Mon Dec 31 2018(Updated: )
A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Videolan Vlc For Mobile | <3.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19937 is a vulnerability in the VideoLAN VLC media player app for iOS that allows a local authenticated attacker to bypass the passcode by opening a URL and turning the phone.
An attacker with local authentication can exploit CVE-2018-19937 by opening a URL and turning the phone to bypass the passcode in the VLC media player app for iOS.
CVE-2018-19937 has a severity level of medium with a CVSS score of 6.6.
CVE-2018-19937 affects versions of the VideoLAN VLC media player app for iOS before 3.1.5.
Yes, upgrading to version 3.1.5 of the VideoLAN VLC media player app for iOS will fix CVE-2018-19937.