CVE-2019-9720: Libav

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted video file in Matroska format, because srt_to_ass in libavcodec/srtdec.c misuses snprintf.

Affected products

  • Libav Libav: up to and including 12.3

Published 2019-09-19. Last modified 2026-06-17.