VDB

CVE-2019-12874

CVE-2019-12874 PUBLISHED CVSS 9.800000190734863 CRITICAL

An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.

EPSS 2.39% · 83.3th percentile

Risk Scores

CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
2.39%
83.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSvlc0, 2.2.1-5, 2.2.2-1
Ubuntu:18.04:LTSvlc0, 2.2.6-6, 2.2.6-6build1

Timeline

  • Jun 18, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Oct 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 15, 2022 EPSS Score
  • Sep 7, 2022 EPSS Score
  • Nov 9, 2022 EPSS Score
  • Feb 28, 2023 EPSS Score
  • Mar 15, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›