CVE-2019-14498: Divide by Zero
Published Aug 29, 2019
·Updated
A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
Affected Software
4 affected componentsFixes available
Videolan VLC Media Player=3.0.7.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/vlc
3.0.21-0+deb11u13.0.22-0+deb12u13.0.23-0+deb12u13.0.23-0+deb13u13.0.23-1
Remediation
Patch Available
Event History
Aug 29, 2019
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·11:06 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:06 PM
Description
Mar 14, 2026
Data Sourced
via Debian·11:26 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-14498?
CVE-2019-14498 is a vulnerability in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1 that allows a divide-by-zero error to be triggered via a crafted CAF file.
2
What is the severity of CVE-2019-14498?
CVE-2019-14498 has a severity level of 7.8 (high).
3
How does CVE-2019-14498 impact VLC media player?
CVE-2019-14498 can trigger a divide-by-zero error in the Control function of demux/caf.c in VLC media player 3.0.7.1 when processing a specially crafted CAF file.
4
Which versions of VLC media player are affected by CVE-2019-14498?
VLC media player version 3.0.7.1 is affected by CVE-2019-14498.
5
How can I remediate CVE-2019-14498 in VLC media player?
To remediate CVE-2019-14498, update VLC media player to version 3.0.8 or higher.