CVE-2019-14777: Use After Free
Published Aug 29, 2019
·Updated
Last updated 26 August 2025
Other sources
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
— MITRE
Affected Software
4 affected componentsFixes available
Videolan VLC Media Player=3.0.7.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/vlc
3.0.21-0+deb11u13.0.22-0+deb12u13.0.23-0+deb12u13.0.23-0+deb13u13.0.23-1
Remediation
Patch Available
Event History
Aug 29, 2019
CVE Published
via MITRE·06:53 PM
Data Sourced
via MITRE·06:53 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·11:06 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:06 PM
Description
Mar 14, 2026
Data Sourced
via Debian·11:26 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability CVE-2019-14777?
The vulnerability CVE-2019-14777 is a use-after-free vulnerability in the Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1.
2
How does the vulnerability CVE-2019-14777 affect VLC media player?
The vulnerability CVE-2019-14777 can be exploited to execute arbitrary code or cause a denial-of-service condition.
3
What is the severity of the vulnerability CVE-2019-14777?
The severity of the vulnerability CVE-2019-14777 is rated as high with a CVSS score of 7.8.
4
What are the affected versions of VLC media player?
The affected versions of VLC media player include 3.0.7.1.
5
How can I fix the vulnerability CVE-2019-14777 in VLC media player?
To fix the vulnerability CVE-2019-14777 in VLC media player, update to version 3.0.8-0ubuntu18.04.1 or later.