First published: Thu Aug 29 2019(Updated: )
A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Videolan Vlc Media Player | =3.0.7.1 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
debian/vlc | 3.0.21-0+deb11u1 3.0.21-0+deb12u1 3.0.21-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14498 is a vulnerability in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1 that allows a divide-by-zero error to be triggered via a crafted CAF file.
CVE-2019-14498 has a severity level of 7.8 (high).
CVE-2019-14498 can trigger a divide-by-zero error in the Control function of demux/caf.c in VLC media player 3.0.7.1 when processing a specially crafted CAF file.
VLC media player version 3.0.7.1 is affected by CVE-2019-14498.
To remediate CVE-2019-14498, update VLC media player to version 3.0.8 or higher.