First published: Fri May 15 2020(Updated: )
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Videolan Vlc Media Player | <3.0.9 |
https://git.videolan.org/?p=vlc/vlc-3.0.git;a=commit;h=72afe7ebd8305bf4f5360293b8621cde52ec506b
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-19721.
The severity of CVE-2019-19721 is high with a CVSS score of 7.8.
The vulnerability CVE-2019-19721 can be exploited by remote attackers to cause a denial of service (memory corruption) through a crafted image file.
The Videolan Vlc Media Player version up to exclusive 3.0.9 is affected by CVE-2019-19721.
Yes, a fix is available. It is recommended to update to a version of Videolan Vlc Media Player beyond 3.0.9 to mitigate the vulnerability.