CVE-2019-13962: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
Affected products
- Canonical Ubuntu Linux: version 18.04 only; version 19.04 only
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Opensuse Backports Sle: version 15.0 only
- Opensuse Leap: version 15.0 only; version 15.1 only
- Videolan Vlc Media Player: up to and including 3.0.7
Published 2019-07-18. Last modified 2026-10-08.