GHSA-2wrf-hf7j-cx32MediumCVSS 7.8
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player...
🔗 CVE IDs covered (1)
📋 Description
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2019-19721
- https://bugs.gentoo.org/721940
- https://git.videolan.org/?p=vlc/vlc-3.0.git;a=commit;h=72afe7ebd8305bf4f5360293b8621cde52ec506b
- https://git.videolan.org/?p=vlc/vlc-3.0.git%3Ba=commit%3Bh=72afe7ebd8305bf4f5360293b8621cde52ec506b
- https://www.videolan.org/security
- http://hg.libsdl.org/SDL_image
- https://github.com/advisories/GHSA-2wrf-hf7j-cx32