CVE-2019-12951

Publication date 24 June 2019

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer overflow.

Read the notes from the security team

Status

Package Ubuntu Release Status
smplayer 19.04 disco Ignored
18.10 cosmic Ignored end of life
18.04 LTS bionic Ignored
16.04 LTS xenial
Not affected
14.04 LTS trusty Not in release

Notes


alexmurray

smplayer in >= bionic contains an embedded copy of mongoose


ebarretto

smplayer embeds a copy, which is unused in any released version and disabled since 18.5.0~ds1-1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
smplayer

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities