Related Vulnerabilities: CVE-2019-5439  

VideoLAN VLC media player 3.0.6 and earlier has a out-of-bounds write has been found in the ReadFrame function of the AVI decoder.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

VideoLAN VLC media player 3.0.6 and earlier has a out-of-bounds write has been found in the ReadFrame function of the AVI decoder.

AVG-998 vlc 3.0.6-13 3.0.7.1-1 Critical Fixed

https://www.videolan.org/security/sa1901.html
https://hackerone.com/reports/484398