Use-after-free in libebml - CVE-2015-8789
Published: January 29, 2016 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing a "deeply nested element with infinite size" followed by another element of an upper level in an EBML document. <a href="http://cwe.mitre.org/data/definitions/416. A context-dependent attackers can have unspecified impact.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
libebml (Alpine package)
libebml
Fedora
IBM Tivoli Storage Manager
How to mitigate CVE-2015-8789
libebml (Alpine package) - update to 1.3.3-r0
libebml - addressed in versions 1.2.2-1.el6, 1.3.3-3.el7
IBM Tivoli Storage Manager - update to 5.3.6.6
External References
- http://lists.matroska.org/pipermail/matroska-users/2015-October/006985.html
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00035.html
- http://www.debian.org/security/2016/dsa-3538
- http://www.securityfocus.com/bid/94924
- http://www.talosintelligence.com/reports/TALOS-2016-0037/
- https://github.com/Matroska-Org/libebml/blob/release-1.3.3/ChangeLog
- https://github.com/Matroska-Org/libebml/commit/88409e2a94dd3b40ff81d08bf6d92f486d036b24