CVE-2019-19721
גבוהה 7.8
תיאור (מקור, אנגלית)
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CWE
- CWE-193, CWE-787
מוצרים מושפעים
videolan: vlc media player
קישורים
- https://www.videolan.org/security/ Vendor Advisory
- https://www.videolan.org/security/ Vendor Advisory
- https://bugs.gentoo.org/721940 ExploitPatchThird Party Advisory
- https://bugs.gentoo.org/721940 ExploitPatchThird Party Advisory
- http://hg.libsdl.org/SDL_image/ Release NotesThird Party Advisory
- https://git.videolan.org/?p=vlc/vlc-3.0.git%3Ba=commit%3Bh=72afe7ebd8305bf4f53…
- http://hg.libsdl.org/SDL_image/ Release NotesThird Party Advisory
- https://git.videolan.org/?p=vlc/vlc-3.0.git%3Ba=commit%3Bh=72afe7ebd8305bf4f53…