---
id: CVE-2019-13602
title: >-
  An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in
  VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a
  denial of service (heap-based buffer overflow and crash) or possibly have
  unspecified…
summary: >-
  An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in
  VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a
  denial of service (heap-based buffer overflow and crash) or possibly have
  unspecified…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-191
  - CWE-787
vendor: videolan
product: vlc_media_player
affected:
  - vlc_media_player <= 3.0.7.1
  - debian_linux = 9.0
  - debian_linux = 10.0
  - ubuntu_linux = 18.04
  - ubuntu_linux = 19.04
  - backports_sle = 15.0
  - leap = 15.0
  - leap = 15.1
published: '2019-07-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:49.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-13602'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.html'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.html'
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/109158'
    label: cve@mitre.org
  - url: >-
      https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=8e8e0d72447f8378244f5b4a3dcde036dbeb1491
    label: cve@mitre.org
  - url: >-
      https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=b2b157076d9e94df34502dd8df0787deb940e938
    label: cve@mitre.org
  - url: 'https://seclists.org/bugtraq/2019/Aug/36'
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/201909-02'
    label: cve@mitre.org
  - url: 'https://usn.ubuntu.com/4074-1/'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2019/dsa-4504'
    label: cve@mitre.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/109158'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=8e8e0d72447f8378244f5b4a3dcde036dbeb1491
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.videolan.org/?p=vlc.git%3Ba=commit%3Bh=b2b157076d9e94df34502dd8df0787deb940e938
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/bugtraq/2019/Aug/36'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/201909-02'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4074-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2019/dsa-4504'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02098
epssPercentile: 0.81106
ingestedAt: '2026-10-08T23:16:47.296Z'
---

## Overview

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

## Affected

- `vlc_media_player <= 3.0.7.1`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `ubuntu_linux = 18.04`
- `ubuntu_linux = 19.04`
- `backports_sle = 15.0`
- `leap = 15.0`
- `leap = 15.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
