Integer underflow in VLC Media Player - CVE-2019-5459
Published: August 8, 2019
Vulnerability identifier: #VU19982
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5459
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to integer underflow when processing FAAD2 media files. A remote attacker can create a specially crafted media file, trick the victim to open it, trigger integer underflow and crash the affected application.
Affected software
VLC Media Player
Opensuse
SUSE Linux
Opensuse
SUSE Linux
How to mitigate CVE-2019-5459
Install updates from vendor's website.
VLC Media Player - update to 3.0.7