Vulnerability Description
libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Videolan | Vlc Media Player | < 3.0.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/109304Third Party AdvisoryVDB Entry
- https://github.com/Matroska-Org/libebml/commit/05beb69ba60acce09f73ed491bb76f332
- https://github.com/Matroska-Org/libebml/commit/b66ca475be967547af9a3784e720fbbac
- https://github.com/Matroska-Org/libebml/compare/release-1.3.5...release-1.3.6
- https://trac.videolan.org/vlc/ticket/22474ExploitIssue TrackingVendor Advisory
- https://usn.ubuntu.com/4073-1/
- http://www.securityfocus.com/bid/109304Third Party AdvisoryVDB Entry
- https://github.com/Matroska-Org/libebml/commit/05beb69ba60acce09f73ed491bb76f332
- https://github.com/Matroska-Org/libebml/commit/b66ca475be967547af9a3784e720fbbac
- https://github.com/Matroska-Org/libebml/compare/release-1.3.5...release-1.3.6
- https://trac.videolan.org/vlc/ticket/22474ExploitIssue TrackingVendor Advisory
- https://usn.ubuntu.com/4073-1/
FAQ
What is CVE-2019-13615?
CVE-2019-13615 is a vulnerability with a CVSS score of 5.5 (MEDIUM). libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.
How severe is CVE-2019-13615?
CVE-2019-13615 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13615?
Check the references section above for vendor advisories and patch information. Affected products include: Videolan Vlc Media Player.