CVE-2019-13602: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 19.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Videolan Vlc Media Player: up to and including 3.0.7.1
Published 2019-07-14. Last modified 2026-10-08.