Information disclosure in libebml - CVE-2015-8791
Published: January 29, 2016 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access.
Affected software
libebml (Alpine package)
libebml
Fedora
IBM Tivoli Storage Manager
How to mitigate CVE-2015-8791
libebml (Alpine package) - update to 1.3.3-r0
libebml - addressed in versions 1.2.2-1.el6, 1.3.3-3.el7
IBM Tivoli Storage Manager - update to 5.3.6.6
External References
- http://lists.matroska.org/pipermail/matroska-users/2015-October/006985.html
- http://lists.opensuse.org/opensuse-updates/2016-01/msg00035.html
- http://www.debian.org/security/2016/dsa-3538
- https://github.com/Matroska-Org/libebml/blob/release-1.3.3/ChangeLog
- https://github.com/Matroska-Org/libebml/commit/24e5cd7c666b1ddd85619d60486db0a5481c1b90