CVE-2019-18278: High severity vlc media player vulnerability
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqtplugin!vlcentrylicense300f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18278?
The severity of CVE-2019-18278 is high with a severity value of 7.8.
Which software is affected by CVE-2019-18278?
Videolan VLC media player version 3.0.8 is affected by CVE-2019-18278.
What is the vulnerability description of CVE-2019-18278?
CVE-2019-18278 allows an attacker to control the code flow when executing Videolan VLC media player 3.0.8 with libqt on Windows.
Is Microsoft Windows vulnerable to CVE-2019-18278?
No, Microsoft Windows is not vulnerable to CVE-2019-18278.
How can I find more information about CVE-2019-18278?
You can find more information about CVE-2019-18278 at [this link](https://code610.blogspot.com/2019/10/random-bytes-in-vlc-308.html).