CVE-2019-14970: Buffer Overflow
Published Aug 29, 2019
·Updated
A vulnerability in mkv::eventthreadt in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
Affected Software
4 affected componentsFixes available
Videolan VLC Media Player=3.0.7.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/vlc
3.0.21-0+deb11u13.0.22-0+deb12u13.0.23-0+deb12u13.0.23-0+deb13u13.0.23-1
Remediation
Patch Available
Event History
Aug 29, 2019
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·11:06 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:06 PM
Description
Mar 14, 2026
Data Sourced
via Debian·11:26 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-14970?
CVE-2019-14970 is a vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1.
2
How does CVE-2019-14970 affect the VLC media player?
CVE-2019-14970 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
3
Which versions of VLC media player are affected by CVE-2019-14970?
VLC media player 3.0.7.1 is affected by CVE-2019-14970.
4
How severe is CVE-2019-14970?
CVE-2019-14970 has a severity rating of 7.8 (high).
5
How can I fix the CVE-2019-14970 vulnerability?
To fix the CVE-2019-14970 vulnerability, update VLC media player to version 3.0.8-0ubuntu18.04.1 (for Ubuntu) or apply the appropriate security patches for your OS.