Back to Database
Status published
Medium
CVE-2019-13615
libebml before 1.3.6, as used in the MKV module in...
Vulnerability Description
libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13615
Credits & Attribution
No credits recorded in the NVD database.
References
- https://trac.videolan.org/vlc/ticket/22474
- http://www.securityfocus.com/bid/109304
- https://github.com/Matroska-Org/libebml/commit/05beb69ba60acce09f73ed491bb76f332849c3a0
- https://github.com/Matroska-Org/libebml/compare/release-1.3.5...release-1.3.6
- https://usn.ubuntu.com/4073-1/
- https://github.com/Matroska-Org/libebml/commit/b66ca475be967547af9a3784e720fbbacd381be6
More from videolan
View All →CVE-2022-41325
An integer overflow in the VNC module in VideoLAN VLC...
Unknown
0
CVE-2021-25804
A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC...
High
7.5
CVE-2021-25803
A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN...
High
7.1
CVE-2021-25802
A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN...
High
7.1
CVE-2021-25801
A buffer overflow vulnerability in the __Parse_indx component of VideoLAN...
High
7.1
Affected Vendor
videolan
View all reports →Affected Software
vlc media player
Vulnerable Versions:
0
Timeline
Official Publish:
July 16th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.