First published: Sun Jul 14 2019(Updated: )
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Videolan Vlc Media Player | <=3.0.7.1 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
openSUSE Backports SLE | =15.0 | |
openSUSE Backports SLE | =15.0-sp1 | |
openSUSE Leap | =15.0 | |
openSUSE Leap | =15.1 | |
debian/vlc | 3.0.21-0+deb11u1 3.0.21-0+deb12u1 3.0.21-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13602 is an Integer Underflow vulnerability in VideoLAN VLC media player that allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mp4 file.
The severity of CVE-2019-13602 is high with a CVSS score of 7.8.
CVE-2019-13602 affects VideoLAN VLC media player versions up to and including 3.0.7.1.
Yes, there are fixed versions available for CVE-2019-13602. For Debian, the fixed versions are 3.0.17.4-0+deb10u1, 3.0.17.4-0+deb10u2, 3.0.18-0+deb11u1, 3.0.18-2, and 3.0.19-1. For Ubuntu, the fixed version is 3.0.7.1-0ubuntu18.04.1 for Bionic and 3.0.7.1-0ubuntu19.04.1 for Disco. Additionally, there is a fixed version 3.0.7.1-2 available from upstream for Ubuntu.
More information about CVE-2019-13602 can be found in the following references: [link1], [link2], [link3].