Security Vulnerabilities fixed in VideoLAN VideoLAN-SA-1901

description-logoDescription

A remote user can create some specially crafted avi or mkv files that, when loaded by the target user, will trigger a heap buffer overflow (read) in ReadFrame (demux/avi/avi.c), or a double free in zlib_decompress_extra() (demux/mkv/utils.cpp) respectively

affected-products-logoAffected Applications

VLC Media Player

CVE References

CVE-2019-5439 CVE-2019-12874