Vulnerability identifier: #VU19981
Vulnerability risk: Low
CVSSv4.0: 1.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Clear]
CVE-ID: CVE-2019-5460
CWE-ID:
CWE-415
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
VLC Media Player
Client/Desktop applications /
Multimedia software
Vendor: VideoLAN
Description
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing media files in the modules/codec/faad.c file. A remote attacker can trick the victim to open a specially crafted media file, trigger double free error and crash the application.Mitigation
Install updates from vendor's website.
Vulnerable software versions
VLC Media Player: 3.0.0 - 3.0.6
External links
https://hackerone.com/reports/503208
https://github.com/videolan/vlc/commit/f256bf045c2b1f7395f61b2039a67f18aee66673
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.