NULL pointer dereference in VLC Media Player - CVE-2019-14534
Published: September 12, 2019
Vulnerability identifier: #VU21093
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14534
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error in the SeekPercent() function in demux/asf/asf.c. A remote attacker can use a specially crfated media file to perform denial of service (DoS) attack.
Affected software
VLC Media Player
Gentoo Linux
SUSE Linux
Opensuse
vlc (Alpine package)
Gentoo Linux
SUSE Linux
Opensuse
vlc (Alpine package)
How to mitigate CVE-2019-14534
Install update from vendor's website.
VLC Media Player - update to 3.0.8
vlc (Alpine package) - update to 3.0.8-r0
vlc (Alpine package) - update to 3.0.8-r0