CVE-2019-19721: High severity vlc media player vulnerability
Published May 15, 2020
·Updated
An off-by-one error in the DecodeBlock function in codec/sdlimage.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDLImage product.
Affected Software
1 affected component
Videolan VLC Media Player<3.0.9
Remediation
Patch Available
Event History
May 15, 2020
CVE Published
via MITRE·05:28 PM
Data Sourced
via MITRE·05:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-19721.
2
What is the severity of CVE-2019-19721?
The severity of CVE-2019-19721 is high with a CVSS score of 7.8.
3
How can the vulnerability CVE-2019-19721 be exploited?
The vulnerability CVE-2019-19721 can be exploited by remote attackers to cause a denial of service (memory corruption) through a crafted image file.
4
Which software is affected by CVE-2019-19721?
The Videolan Vlc Media Player version up to exclusive 3.0.9 is affected by CVE-2019-19721.
5
Is there a fix available for CVE-2019-19721?
Yes, a fix is available. It is recommended to update to a version of Videolan Vlc Media Player beyond 3.0.9 to mitigate the vulnerability.