lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vlc | Nov 8, 2019 | Jul 18, 2019 |
| Debian | — | Upgrade vlc | Aug 22, 2019 | Jul 18, 2019 |
| Freebsd | — | Upgrade vlc | Aug 21, 2019 | Aug 20, 2019 |
| Gentoo Linux | — | Upgrade media-video/vlc. | Sep 9, 2019 | Jul 18, 2019 |
| Suse | — | Upgrade vlcUpgrade vlc-vdpauUpgrade aom-toolsUpgrade vlc-opencvUpgrade libaom0-64bitUpgrade libvlc5Upgrade vlc-noxUpgrade vlc-jackUpgrade libaom0Upgrade libvlccore9Upgrade vlc-develUpgrade libaom-devel-docUpgrade vlc-qtUpgrade vlc-codec-gstreamerUpgrade libaom-develUpgrade vlc-lang | Aug 9, 2019 | Jul 18, 2019 |
| Ubuntu | — | Upgrade vlc | Sep 12, 2019 | Jul 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub