CVE-2019-5459Integer Underflow (Wrap or Wraparound) in VLC Media Player

Severity
7.1HIGHNVD
EPSS
1.2%
top 21.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateMay 24

Description

An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages6 packages

Debianvideolan/vlc_media_player< 3.0.7-1+3
CVEListV5videolan/vlc_media_playerFixed in 3.0.7
NVDopensuse/leap15.0, 15.1+1
NVDopensuse/backportssle-15

🔴Vulnerability Details

3
GHSA
GHSA-pvmq-wghp-3g56: An Integer underflow in VLC Media Player versions < 32022-05-24
OSV
CVE-2019-5459: An Integer underflow in VLC Media Player versions < 32019-07-30
CVEList
CVE-2019-5459: An Integer underflow in VLC Media Player versions < 32019-07-30

📋Vendor Advisories

1
Debian
CVE-2019-5459: vlc - An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-ban...2019
CVE-2019-5459 — Integer Underflow (Wrap or Wraparound) | cvebase