CVE-2019-13602: Buffer Overflow
An Integer Underflow in MP4EIA608Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-13602?
CVE-2019-13602 is an Integer Underflow vulnerability in VideoLAN VLC media player that allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mp4 file.
What is the severity of CVE-2019-13602?
The severity of CVE-2019-13602 is high with a CVSS score of 7.8.
How does CVE-2019-13602 affect VideoLAN VLC media player?
CVE-2019-13602 affects VideoLAN VLC media player versions up to and including 3.0.7.1.
Is there a fix available for CVE-2019-13602?
Yes, there are fixed versions available for CVE-2019-13602. For Debian, the fixed versions are 3.0.17.4-0+deb10u1, 3.0.17.4-0+deb10u2, 3.0.18-0+deb11u1, 3.0.18-2, and 3.0.19-1. For Ubuntu, the fixed version is 3.0.7.1-0ubuntu18.04.1 for Bionic and 3.0.7.1-0ubuntu19.04.1 for Disco. Additionally, there is a fixed version 3.0.7.1-2 available from upstream for Ubuntu.
Where can I find more information about CVE-2019-13602?
More information about CVE-2019-13602 can be found in the following references: [link1], [link2], [link3].