Use-After-Free Vulnerability in VideoLAN VLC Media Player
CVE-2019-14777
7.8HIGH
What is CVE-2019-14777?
The VLC Media Player, specifically version 3.0.7.1, has a vulnerability in its Control function located in demux/mkv/mkv.cpp that can lead to a use-after-free condition. This vulnerability allows an attacker to potentially execute arbitrary code or crash the application, thereby compromising the security of systems running this version. Users are strongly recommended to update their VLC Media Player to mitigate this risk. Security patches addressing this issue have been issued by VideoLAN and various Linux distributions.