|
|
Log in / Subscribe / Register

libebml: two vulnerabilities

Package(s):libebml CVE #(s):CVE-2015-8790 CVE-2015-8791
Created:February 29, 2016 Updated:March 2, 2016
Description: From the CVE entries:

The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid memory access. (CVE-2015-8790)

The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access. (CVE-2015-8791)

Alerts:
Debian DSA-3538-1 libebml 2016-03-31
Debian-LTS DLA-438-1 libebml 2016-02-28

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds