SB2019072931 - Integer underflow in vlc (Alpine package)
Published: July 29, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer underflow (CVE-ID: CVE-2019-13602)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attacks on the target system.
The vulnerability exists due to a boundary error in the "MP4_EIA608_Convert()" function in the "modules/demux/mp4/mp4.c" file. A remote attacker can trick the victim to open a specially crafted .mp4 file, trigger integer underflow and crash the affected application.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1ebe2cad40adfbabf1834c6f475ec127bd6cea76
- https://git.alpinelinux.org/aports/commit/?id=c4cee9ea9b47a4a0340aaa1b9681adab29fc4e57
- https://git.alpinelinux.org/aports/commit/?id=686d2c8ff9d0c366e038254dc3fe3ad3e1fc88f9
- https://git.alpinelinux.org/aports/commit/?id=2ff02c6e30e0c86bea8d48f1f3a96a3561d09945