Discover the impact of CVE-2019-12874 affecting VideoLAN VLC media player 3.x through 3.0.7. Learn about the vulnerability, affected systems, exploitation risks, and mitigation steps.
VideoLAN VLC media player 3.x through 3.0.7 has encountered a bug in zlib_decompress_extra, specifically in modules/demux/mkv/util.cpp. This bug arises when the Matroska demuxer attempts to parse a corrupted MKV file, resulting in a double free action.
Understanding CVE-2019-12874
An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.
What is CVE-2019-12874?
The Impact of CVE-2019-12874
Technical Details of CVE-2019-12874
Affects the VideoLAN VLC media player 3.x through 3.0.7
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
Patching and Updates