CVE-2019-13602: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Videolan Vlc Media Player: up to and including 3.0.7.1

Published 2019-07-14. Last modified 2026-10-08.