CVE Database
/

CVE-2018-19857

Back to search

CVE-2018-19857

Published: Dec 5, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a potential infoleak.

VendorProductVersions

n/a

n/a

affected
n/a

References

106130
vdb-entry
x_refsource_BID
DSA-4366
vendor-advisory
x_refsource_DEBIAN
USN-4074-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2019:1840
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1909
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:1897
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2015
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now