Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2019-14777
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2019-14777
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-14777.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-14777
Downstream
DEBIAN-CVE-2019-14777
DSA-4504-1
UBUNTU-CVE-2019-14777
USN-4131-1
openSUSE-SU-2020:0545-1
openSUSE-SU-2020:0562-1
openSUSE-SU-2024:11502-1
Related
MGASA-2019-0233
openSUSE-SU-2020:0545-1
openSUSE-SU-2020:0562-1
openSUSE-SU-2024:11502-1
Published
2019-08-29T19:15:13Z
Modified
2025-10-13T08:17:31.860367Z
Severity
7.8 (High)
CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
References
http://git.videolan.org/?p=vlc.git&a=search&h=refs/heads/master&st=commit&s=cve-2019
https://seclists.org/bugtraq/2019/Aug/36
https://security.gentoo.org/glsa/201909-02
https://www.debian.org/security/2019/dsa-4504
https://www.videolan.org/security/sb-vlc308.html
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00036.html
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00046.html
https://usn.ubuntu.com/4131-1/
Affected packages
Git
/
github.com/videolan/vlc-3.0
Affected ranges
Type
GIT
Repo
https://github.com/videolan/vlc-3.0
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
f3940db4af197ba7218e604dd0a6733654015770
Affected versions
0.*
0.9.0
0.9.0-test0
0.9.0-test1
0.9.0-test2
0.9.0-test3
1.*
1.0.0-pre1
1.0.0-pre2
1.0.0-rc1
1.1.0-ff
1.1.0-pre1
1.2.0-pre1
1.3.0-git
2.*
2.1.0-git
2.2.0-git
3.*
3.0.0
3.0.0-1
3.0.0-2
3.0.0-git
3.0.0-rc1
3.0.0-rc2
3.0.0-rc3
3.0.0-rc4
3.0.0-rc5
3.0.0-rc6
3.0.0-rc7
3.0.0-rc8
3.0.0.1
3.0.1
3.0.2
3.0.3
3.0.3-1
3.0.4
3.0.5
3.0.5-1
3.0.5-2
3.0.6
3.0.7
3.0.7.1
Other
svn-trunk
CVE-2019-14777 - OSV