Vulnerability CVE-2019-13962: Information

Description

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: July 18, 2019
Modified: Nov. 7, 2023
Error type identifier: CWE-125

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://trac.videolan.org/vlc/ticket/22240
  • Exploit
  • Vendor Advisory
109306
  • Broken Link
openSUSE-SU-2019:1840
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:1909
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:1897
  • Mailing List
  • Third Party Advisory
DSA-4504
  • Third Party Advisory
20190821 [SECURITY] [DSA 4504-1] vlc security update
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:2015
  • Mailing List
  • Third Party Advisory
GLSA-201909-02
  • Third Party Advisory
USN-4131-1
  • Third Party Advisory
openSUSE-SU-2020:0545
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2020:0562
  • Mailing List
  • Third Party Advisory
http://git.videolan.org/?p=vlc/vlc-3.0.git%3Ba=commit%3Bh=2b4f9d0b0e0861f262c90e9b9b94e7d53b864509
      1. Configuration 1

        cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*
        End including
        3.0.7

        Configuration 2

        cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

        cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

        cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*

        cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*

        Configuration 3

        cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

        cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

        Configuration 4

        cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

        cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*