CVE-2019-14438: High severity Videolan VLC Media Player vulnerability
Published Aug 29, 2019
·Updated
A heap-based buffer over-read in xiphPackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.
Affected Software
4 affected componentsFixes available
Videolan VLC Media Player=3.0.7.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/vlc
3.0.21-0+deb11u13.0.22-0+deb12u13.0.23-0+deb12u13.0.23-0+deb13u13.0.23-1
Remediation
Patch Available
Event History
Aug 29, 2019
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·11:06 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:06 PM
Description
Mar 14, 2026
Data Sourced
via Debian·11:26 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-14438?
CVE-2019-14438 is a vulnerability in VideoLAN VLC media player 3.0.7.1 that allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.
2
What is the severity of CVE-2019-14438?
CVE-2019-14438 has a severity score of 7.8 (high).
3
How can CVE-2019-14438 be exploited?
CVE-2019-14438 can be exploited by sending a crafted .ogg file to the vulnerable VLC media player.
4
Which software versions are affected by CVE-2019-14438?
CVE-2019-14438 affects VideoLAN VLC media player 3.0.7.1.
5
How can I fix CVE-2019-14438?
To fix CVE-2019-14438, update your VLC media player to version 3.0.8-0ubuntu18.04.1 or higher.