Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2019-13602: vlc: An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Distribution | Reporter: | Wolfgang Frisch <wolfgang.frisch> |
Component: | Security | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | dimstar |
Version: | Leap 15.0 | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/237119/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Wolfgang Frisch
2019-07-15 15:29:50 UTC
CVE-2019-13615 is not a VLC bug, but a libebml < 1.3.6 issue (In reply to Dominique Leuenberger from comment #1) > CVE-2019-13615 is not a VLC bug, but a libebml < 1.3.6 issue True, but this bug is CVE-2019-13602 (wrong bug reassigneD) This is an autogenerated message for OBS integration: This bug (1141522) was mentioned in https://build.opensuse.org/request/show/719998 15.1 / vlc https://build.opensuse.org/request/show/719999 15.0 / vlc openSUSE-SU-2019:1840-1: An update that fixes 7 vulnerabilities is now available. Category: security (important) Bug References: 1118586,1138354,1138933,1141522,1142161,1143547,1143549 CVE References: CVE-2018-19857,CVE-2019-12874,CVE-2019-13602,CVE-2019-13962,CVE-2019-5439,CVE-2019-5459,CVE-2019-5460 Sources used: openSUSE Leap 15.1 (src): vlc-3.0.7.1-lp151.6.3.1 openSUSE-SU-2019:1897-1: An update that fixes 7 vulnerabilities is now available. Category: security (important) Bug References: 1118586,1138354,1138933,1141522,1142161,1143547,1143549 CVE References: CVE-2018-19857,CVE-2019-12874,CVE-2019-13602,CVE-2019-13962,CVE-2019-5439,CVE-2019-5459,CVE-2019-5460 Sources used: openSUSE Backports SLE-15-SP1 (src): vlc-3.0.7.1-bp151.5.3.3 openSUSE-SU-2019:1909-1: An update that solves 7 vulnerabilities and has three fixes is now available. Category: security (important) Bug References: 1093732,1094893,1118586,1133290,1138354,1138933,1141522,1142161,1143547,1143549 CVE References: CVE-2018-19857,CVE-2019-12874,CVE-2019-13602,CVE-2019-13962,CVE-2019-5439,CVE-2019-5459,CVE-2019-5460 Sources used: openSUSE Leap 15.0 (src): libaom-1.0.0-lp150.2.1, vlc-3.0.7.1-lp150.8.1 openSUSE-SU-2019:2015-1: An update that solves 7 vulnerabilities and has three fixes is now available. Category: security (important) Bug References: 1093732,1094893,1118586,1133290,1138354,1138933,1141522,1142161,1143547,1143549 CVE References: CVE-2018-19857,CVE-2019-12874,CVE-2019-13602,CVE-2019-13962,CVE-2019-5439,CVE-2019-5459,CVE-2019-5460 Sources used: openSUSE Backports SLE-15 (src): libaom-1.0.0-bp150.2.1, vlc-3.0.7.1-bp150.2.6.1 Update has been released |