CVE-2019-13962
published 2019-07-18CVE-2019-13962: lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.60%
88.2th percentile
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | vlc | < vlc 3.0.8-1 (bookworm) | vlc 3.0.8-1 (bookworm) |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| videolan | vlc_media_player | <= 3.0.7 | — |
| videolan | vlc_media_player | >= 0 < 3.0.8-1 | 3.0.8-1 |
| videolan | vlc_media_player | >= 0 < 3.0.8-1 | 3.0.8-1 |
| videolan | vlc_media_player | >= 0 < 3.0.8-1 | 3.0.8-1 |
| videolan | vlc_media_player | >= 0 < 3.0.8-1 | 3.0.8-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VideoLAN VLC Media Player up to 3.0.7 video.c lavc_CopyPicture width/height out-of-bounds (ID 22240 / BID-109306)
vuldb·2026-05-04·CVSS 9.8
CVE-2019-13962 [CRITICAL] VideoLAN VLC Media Player up to 3.0.7 video.c lavc_CopyPicture width/height out-of-bounds (ID 22240 / BID-109306)
A vulnerability has been found in VideoLAN VLC Media Player up to 3.0.7 and classified as critical. This impacts the function lavc_CopyPicture of the file modules/codec/avcodec/video.c. The manipulation of the argument width/height leads to out-of-bounds read.
This vulnerability is listed as CVE-2019-13962. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
GHSA
GHSA-g38j-rgpp-8873: lavc_CopyPicture in modules/codec/avcodec/video
ghsa_unreviewed·2022-05-24
CVE-2019-13962 [CRITICAL] CWE-125 GHSA-g38j-rgpp-8873: lavc_CopyPicture in modules/codec/avcodec/video
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
OSV
CVE-2019-13962: lavc_CopyPicture in modules/codec/avcodec/video
osv·2019-07-18·CVSS 9.8
CVE-2019-13962 [CRITICAL] CVE-2019-13962: lavc_CopyPicture in modules/codec/avcodec/video
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
Ubuntu
VLC vulnerabilities
vendor_ubuntu·2019-09-11
CVE-2019-13962 VLC vulnerabilities
Title: VLC vulnerabilities
Summary: Several security issues were fixed in VLC.
It was discovered that VLC incorrectly handled certain media files. If a
user were tricked into opening a specially-crafted file, a remote attacker
could use this issue to cause VLC to crash, resulting in a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-13962: vlc - lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player t...
vendor_debian·2019·CVSS 9.8
CVE-2019-13962 [CRITICAL] CVE-2019-13962: vlc - lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player t...
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
Scope: local
bookworm: resolved (fixed in 3.0.8-1)
bullseye: resolved (fixed in 3.0.8-1)
forky: resolved (fixed in 3.0.8-1)
sid: resolved (fixed in 3.0.8-1)
trixie: resolved (fixed in 3.0.8-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.videolan.org/?p=vlc/vlc-3.0.git%3Ba=commit%3Bh=2b4f9d0b0e0861f262c90e9b9b94e7d53b864509http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.htmlhttp://www.securityfocus.com/bid/109306https://seclists.org/bugtraq/2019/Aug/36https://security.gentoo.org/glsa/201909-02https://trac.videolan.org/vlc/ticket/22240https://usn.ubuntu.com/4131-1/https://www.debian.org/security/2019/dsa-4504http://git.videolan.org/?p=vlc/vlc-3.0.git%3Ba=commit%3Bh=2b4f9d0b0e0861f262c90e9b9b94e7d53b864509http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.htmlhttp://www.securityfocus.com/bid/109306https://seclists.org/bugtraq/2019/Aug/36https://security.gentoo.org/glsa/201909-02https://trac.videolan.org/vlc/ticket/22240https://usn.ubuntu.com/4131-1/https://www.debian.org/security/2019/dsa-4504
2019-07-18
Published