Unrated severityNVD Advisory· Published Jul 14, 2019· Updated Aug 4, 2024
CVE-2019-13602
CVE-2019-13602
Description
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
Affected products
8- VideoLAN/VLC media playerdescription
- osv-coords7 versionspkg:rpm/opensuse/libaom&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/vlc&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/vlc&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libaom&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/vlc&distro=SUSE%20Package%20Hub%2015%20SP1
< 1.0.0-lp150.2.1+ 6 more
- (no CPE)range: < 1.0.0-lp150.2.1
- (no CPE)range: < 3.0.7.1-lp150.8.1
- (no CPE)range: < 3.0.7.1-lp151.6.3.1
- (no CPE)range: < 3.0.16-1.5
- (no CPE)range: < 1.0.0-bp150.2.1
- (no CPE)range: < 3.0.7.1-bp150.2.6.1
- (no CPE)range: < 3.0.7.1-bp151.5.3.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.htmlmitrevendor-advisoryx_refsource_SUSE
- security.gentoo.org/glsa/201909-02mitrevendor-advisoryx_refsource_GENTOO
- usn.ubuntu.com/4074-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2019/dsa-4504mitrevendor-advisoryx_refsource_DEBIAN
- www.securityfocus.com/bid/109158mitrevdb-entryx_refsource_BID
- git.videolan.orgmitrex_refsource_MISC
- git.videolan.orgmitrex_refsource_MISC
- seclists.org/bugtraq/2019/Aug/36mitremailing-listx_refsource_BUGTRAQ
News mentions
0No linked articles in our index yet.