{"id":"CVE-2019-13602","title":"An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified…","summary":"An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-191","CWE-787"],"vendor":"videolan","product":"vlc_media_player","affected":["vlc_media_player <= 3.0.7.1","debian_linux = 9.0","debian_linux = 10.0","ubuntu_linux = 18.04","ubuntu_linux = 19.04","backports_sle = 15.0","leap = 15.0","leap = 15.1"],"published":"2019-07-14","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:49.780","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-13602","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.html","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/109158","label":"cve@mitre.org"},{"url":"https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=8e8e0d72447f8378244f5b4a3dcde036dbeb1491","label":"cve@mitre.org"},{"url":"https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=b2b157076d9e94df34502dd8df0787deb940e938","label":"cve@mitre.org"},{"url":"https://seclists.org/bugtraq/2019/Aug/36","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/201909-02","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4074-1/","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2019/dsa-4504","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/109158","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=8e8e0d72447f8378244f5b4a3dcde036dbeb1491","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=b2b157076d9e94df34502dd8df0787deb940e938","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://seclists.org/bugtraq/2019/Aug/36","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/201909-02","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4074-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2019/dsa-4504","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02098,"epssPercentile":0.81106,"ingestedAt":"2026-10-08T23:16:47.296Z","slug":"CVE-2019-13602","body":"## Overview\n\nAn Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.\n\n## Affected\n\n- `vlc_media_player <= 3.0.7.1`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 19.04`\n- `backports_sle = 15.0`\n- `leap = 15.0`\n- `leap = 15.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}