First published: Tue Jun 18 2019(Updated: )
An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Videolan Vlc Media Player | >=3.0.0<=3.0.7 | |
debian/vlc | 3.0.21-0+deb11u1 3.0.21-0+deb12u1 3.0.21-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12874 is a vulnerability in VideoLAN VLC media player 3.x through 3.0.7 that allows for a double free when parsing a malformed MKV file type.
CVE-2019-12874 has a severity rating of 9.8 (critical).
The affected software includes VideoLAN VLC media player versions 3.x through 3.0.7 and some Ubuntu and Debian packages.
To fix CVE-2019-12874, you should update your VideoLAN VLC media player to version 3.0.7.1 or higher, or apply the recommended updates for the affected Ubuntu and Debian packages.
You can find more information about CVE-2019-12874 at the references provided: http://git.videolan.org/?p=vlc.git;a=commit;h=81023659c7de5ac2637b4a879195efef50846102, http://www.securityfocus.com/bid/108882, and https://usn.ubuntu.com/4074-1/