vulnerability

FreeBSD: VID-795442E7-C355-11E9-8224-5404A68AD561 (CVE-2019-14970): vlc -- multiple vulnerabilities

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jul 14, 2019
Added
Aug 21, 2019
Modified
Sep 17, 2019

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.


From VID-795442E7-C355-11E9-8224-5404A68AD561:




The VLC project reports:



Security:


* Fix a buffer overflow in the MKV demuxer (CVE-2019-14970)


* Fix a read buffer overflow in the avcodec decoder (CVE-2019-13962)


* Fix a read buffer overflow in the FAAD decoder


* Fix a read buffer overflow in the OGG demuxer (CVE-2019-14437, CVE-2019-14438)


* Fix a read buffer overflow in the ASF demuxer (CVE-2019-14776)


* Fix a use after free in the MKV demuxer (CVE-2019-14777, CVE-2019-14778)


* Fix a use after free in the ASF demuxer (CVE-2019-14533)


* Fix a couple of integer underflows in the MP4 demuxer (CVE-2019-13602)


* Fix a null dereference in the dvdnav demuxer


* Fix a null dereference in the ASF demuxer (CVE-2019-14534)


* Fix a null dereference in the AVI demuxer


* Fix a division by zero in the CAF demuxer (CVE-2019-14498)


* Fix a division by zero in the ASF demuxer (CVE-2019-14535)




Solution

freebsd-upgrade-package-vlc
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.