Back to Database
Status published
Medium
CVE-2019-11372
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in...
Vulnerability Description
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11372
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/MediaArea/MediaInfoLib/pull/1111
- https://sourceforge.net/p/mediainfo/bugs/1101/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BYKBAXS35KFMU4YLO37VGDIKHEL5HSPO/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B752JY7TABWSVYHFATD37XDD6PVIO5C6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BC4Z4BGGMSSVTRKVD3OCW4JLH3K2ZNGP/
- https://usn.ubuntu.com/3988-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XYF5I42OBJR7HKJD2OFS6LP26I52IT3M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XOA4AWTRLWVQBZZAKXXQHP7M2NK6CB3Z/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJYASICJ2VUUNGHDBB62FGYQN2SNITM5/
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00069.html
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00083.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00028.html
More from mediaarea
View All →CVE-2020-26797
Mediainfo before version 20.08 has a heap buffer overflow vulnerability...
High
7.5
CVE-2020-15395
In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based...
High
7.8
CVE-2019-11373
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in...
Medium
6.5
Affected Vendor
mediaarea
View all reports →Affected Software
mediainfo, fedora
Vulnerable Versions:
18.12, 28, 29, 30
Timeline
Official Publish:
April 20th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.