Bug ID 1141522
Summary VUL-0: CVE-2019-13602: An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c allows remote attackers to cause a denial of service (heap-based buffer overflow and crash)
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.0
Hardware Other
URL https://smash.suse.de/issue/237119/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee dimstar@opensuse.org
Reporter wolfgang.frisch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2019-13602

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in
VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a
denial of service (heap-based buffer overflow and crash) or possibly have
unspecified other impact via a crafted .mp4 file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-13602
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13602
http://www.cvedetails.com/cve/CVE-2019-13602/
https://git.videolan.org/?p=vlc.git;a=commit;h=b2b157076d9e94df34502dd8df0787deb940e938
https://git.videolan.org/?p=vlc.git;a=commit;h=8e8e0d72447f8378244f5b4a3dcde036dbeb1491


You are receiving this mail because: