An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libebml ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0438-1 Rating: important References: #1218432 Cross-References: CVE-2023-52339 Affected Products: openSUSE Backports SLE-15-SP6 openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libebml fixes the following issues: - update to 1.4.5 (boo#1218432, CVE-2023-52339): * Fix invalid memory access (reading beyond allocated memory) due to missing integer overflow check. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-438=1 - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-438=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): libebml-debugsource-1.4.5-bp157.2.3.1 libebml-devel-1.4.5-bp157.2.3.1 libebml5-1.4.5-bp157.2.3.1 libebml5-debuginfo-1.4.5-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (aarch64_ilp32): libebml5-64bit-1.4.5-bp157.2.3.1 libebml5-64bit-debuginfo-1.4.5-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (x86_64): libebml5-32bit-1.4.5-bp157.2.3.1 libebml5-32bit-debuginfo-1.4.5-bp157.2.3.1 - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): libebml-devel-1.4.5-bp156.3.3.1 libebml5-1.4.5-bp156.3.3.1 - openSUSE Backports SLE-15-SP6 (aarch64_ilp32): libebml5-64bit-1.4.5-bp156.3.3.1 - openSUSE Backports SLE-15-SP6 (x86_64): libebml5-32bit-1.4.5-bp156.3.3.1 References: https://www.suse.com/security/cve/CVE-2023-52339.html https://bugzilla.suse.com/1218432 . An important update for openSUSE addresses a critical issue in libebml to prevent memory access errors effectively.. libebml update, openSUSE patch, memory access issue. . Severity: Important. LinuxSecurity.com Team
An integer overflow in MemIOCallback::read() has been fixed in libebml, a library for the EBML (Extensible Binary Meta Language) format. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4023-1
Fixes CVE-2023-52339. No API or ABI changes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-7261a9f668 2024-02-05 01:45:31.502972 -------------------------------------------------------------------------------- Name : libebml Product : Fedora 38 Version : 1.4.5 Release : 1.fc38 URL : https://www.matroska.org/index.html Summary : Extensible Binary Meta Language library Description : Extensible Binary Meta Language access library A library for reading and writing files with the Extensible Binary Meta Language, a binary pendant to XML. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2023-52339. No API or ABI changes. -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 2 2024 Dominik Mierzejewski - 1.4.5-1 - update to 1.4.5 (#2254413) - fixes CVE-2023-52339 (#2258046, #2258047) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258046 - CVE-2023-52339 libebml: integer overflow in MemIOCallback::read https://bugzilla.redhat.com/show_bug.cgi?id=2258046 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-7261a9f668' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2023-52339. No API or ABI changes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ab879eeed1 2024-02-05 01:23:58.727183 -------------------------------------------------------------------------------- Name : libebml Product : Fedora 39 Version : 1.4.5 Release : 1.fc39 URL : https://www.matroska.org/index.html Summary : Extensible Binary Meta Language library Description : Extensible Binary Meta Language access library A library for reading and writing files with the Extensible Binary Meta Language, a binary pendant to XML. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2023-52339. No API or ABI changes. -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 2 2024 Dominik Mierzejewski - 1.4.5-1 - update to 1.4.5 (#2254413) - fixes CVE-2023-52339 (#2258046, #2258047) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258046 - CVE-2023-52339 libebml: integer overflow in MemIOCallback::read https://bugzilla.redhat.com/show_bug.cgi?id=2258046 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ab879eeed1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A heap-based buffer overflow in libeml might allow attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202208-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: libebml: Heap buffer overflow vulnerability Date: August 14, 2022 Bugs: #772272 ID: 202208-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A heap-based buffer overflow in libeml might allow attackers to execute arbitrary code. Background ========= libebml is a C++ library to parse EBML files. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libebml < 1.4.2 > = 1.4.2 Description ========== On 32bit builds of libebml, the length of a string is miscalculated, potentially leading to an exploitable heap overflow. Impact ===== An attacker able to provide arbitrary input to libebml could achieve arbitrary code execution. Workaround ========= There is no known workaround at this time. Resolution ========= Users of libebml on 32 bit architectures should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libebml-1.4.2" References ========= [ 1 ] CVE-2021-3405 https://nvd.nist.gov/vuln/detail/CVE-2021-3405 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202208-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users'machines is of utmost importance to us. Any security concerns should be addressed to
A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml (CVE-2021-3405). References: . MGASA-2021-0338 - Updated libebml packages fix a security vulnerability Publication date: 10 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0338.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3405 A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml (CVE-2021-3405). References: - https://bugs.mageia.org/show_bug.cgi?id=29222 - https://lists.fedoraproject.org/archives/list/
Updated libebml packages fix security vulnerabilities: Heap use-after-free when parsing malformed file. A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml (CVE-2021-3405). . MGASA-2021-0226 - Updated libebml packages fix security vulnerabilities Publication date: 08 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0226.html Type: security Affected Mageia releases: 7 CVE: CVE-2021-3405 Updated libebml packages fix security vulnerabilities: Heap use-after-free when parsing malformed file. A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml (CVE-2021-3405). The mkvtoolnix, libmatroska packages have been rebuilt for the updated libebml. References: - https://bugs.mageia.org/show_bug.cgi?id=28278 - https://lists.fedoraproject.org/archives/list/
A heap overflow issue was detected in libebml, a library to read and write files in the EBML format, a binary pendant to XML. These issues appeared in several ReadData functions of various data type . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2629-1
Get the latest Linux and open source security news straight to your inbox.