CVE-2019-13962: Critical severity vlc media player vulnerability
Published Jul 18, 2019
·Updated
Last updated 24 July 2024
Other sources
lavcCopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
Affected Software
10 affected componentsFixes available
debian/vlc
3.0.21-0+deb11u13.0.21-0+deb12u13.0.21-2
Videolan VLC Media Player<=3.0.7
openSUSE Backports SLE=15.0
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.0
openSUSE Leap=15.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
Remediation
Event History
Jul 18, 2019
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:17 PM
Description
Sep 14, 2024
Data Sourced
via Ubuntu·12:20 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2019-13962?
CVE-2019-13962 is a vulnerability in the VideoLAN VLC media player that allows for a heap-based buffer over-read.
2
How severe is CVE-2019-13962?
CVE-2019-13962 has a severity rating of 9.8, which is considered critical.
3
What is the affected software for CVE-2019-13962?
The affected software for CVE-2019-13962 includes VideoLAN VLC media player versions up to 3.0.7.
4
How can I fix CVE-2019-13962?
You can fix CVE-2019-13962 by updating to VLC media player version 3.0.8 or later.
5
Where can I find more information about CVE-2019-13962?
You can find more information about CVE-2019-13962 in the references provided.