libebml: two vulnerabilities
| Package(s): | libebml | CVE #(s): | CVE-2015-8790 CVE-2015-8791 | ||||||||
| Created: | February 29, 2016 | Updated: | March 2, 2016 | ||||||||
| Description: | From the CVE entries:
The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid memory access. (CVE-2015-8790) The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access. (CVE-2015-8791) | ||||||||||
| Alerts: |
| ||||||||||
