Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Mageia: 2021-0226 Moderate: Libebml Heap Overflow Threat Resolved

mageia
Calendar Grey June 8, 2021
Dist Mageia Esm H88
Revamped libebml libraries resolve significant vulnerabilities, boosting overall security posture against various risks.
Updated libebml packages fix security vulnerabilities: Heap use-after-free when parsing malformed file

Summary

Updated libebml packages fix security vulnerabilities:
Heap use-after-free when parsing malformed file.
A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml (CVE-2021-3405).
The mkvtoolnix, libmatroska packages have been rebuilt for the updated libebml.

References

- https://bugs.mageia.org/show_bug.cgi?id=28278

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7COLX6WFFOI3RIOY2IOXWASU3QKAOWKO/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JNHQI6MDOECJ2HT5GCLEX2DMJFEOWPW7/

- https://lists.debian.org/debian-lts-announce/2021/04/msg00016.html

- https://www.cve.org/CVERecord?id=CVE-2021-3405

Resolution

SRPMS

- 7/core/libebml-1.4.2-1.mga7

- 7/core/mkvtoolnix-32.0.0-2.1.mga7

- 7/core/libmatroska-1.5.0-2.1.mga7

Publication date: 08 Jun 2021
URL: https://advisories.mageia.org/MGASA-2021-0226.html
Type: security
CVE: CVE-2021-3405

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here