Integer underflow in VLC Media Player - CVE-2019-13602
Published: July 18, 2019 / Updated: July 18, 2019
VLC Media Player
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attacks on the target system.
The vulnerability exists due to a boundary error in the "MP4_EIA608_Convert()" function in the "modules/demux/mp4/mp4.c" file. A remote attacker can trick the victim to open a specially crafted .mp4 file, trigger integer underflow and crash the affected application.