Vulnerability Database
Blog
FAQ
Docs
CVE-2019-5460
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2019-5460
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-5460.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-5460
Related
DSA-4459-1
openSUSE-SU-2019:1840-1
openSUSE-SU-2019:1897-1
openSUSE-SU-2019:1909-1
openSUSE-SU-2019:2015-1
openSUSE-SU-2024:11502-1
Published
2019-07-30T21:15:12Z
Modified
2024-10-12T05:17:34.284563Z
Severity
5.5 (Medium)
CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS Calculator
Summary
[none]
Details
Double Free in VLC versions <= 3.0.6 leads to a crash.
References
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html
https://hackerone.com/reports/503208
https://security-tracker.debian.org/tracker/CVE-2019-5460
Affected packages
Debian:11
/
vlc
Package
Name
vlc
Purl
pkg:deb/debian/vlc?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.0.7-1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:12
/
vlc
Package
Name
vlc
Purl
pkg:deb/debian/vlc?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.0.7-1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:13
/
vlc
Package
Name
vlc
Purl
pkg:deb/debian/vlc?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.0.7-1
Ecosystem specific
{ "urgency": "not yet assigned" }
Git
/
github.com/videolan/vlc-3.0
Affected ranges
Type
GIT
Repo
https://github.com/videolan/vlc-3.0
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Last affected
5803e85f73dbfc6ee0059f14c8d857b45a1c20bb
Affected versions
0.*
0.9.0
0.9.0-test0
0.9.0-test1
0.9.0-test2
0.9.0-test3
1.*
1.0.0-pre1
1.0.0-pre2
1.0.0-rc1
1.1.0-ff
1.1.0-pre1
1.2.0-pre1
1.3.0-git
2.*
2.1.0-git
2.2.0-git
3.*
3.0.0
3.0.0-1
3.0.0-2
3.0.0-git
3.0.0-rc1
3.0.0-rc2
3.0.0-rc3
3.0.0-rc4
3.0.0-rc5
3.0.0-rc6
3.0.0-rc7
3.0.0-rc8
3.0.0.1
3.0.1
3.0.2
3.0.3
3.0.3-1
3.0.4
3.0.5
3.0.5-1
3.0.5-2
3.0.6
Other
svn-trunk
CVE-2019-5460 - OSV