MGASA-2021-0226
Dashboard / Vulnerabilities / MGASA-2021-0226
Summary: Updated libebml packages fix security vulnerabilities
Details: Updated libebml packages fix security vulnerabilities: Heap use-after-free when parsing malformed file. A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml (CVE-2021-3405). The mkvtoolnix, libmatroska packages have been rebuilt for the updated libebml.
References: https://advisories.mageia.org/MGASA-2021-0226.html, https://bugs.mageia.org/show_bug.cgi?id=28278, https://lists.fedoraproject.org/archives/list/[email protected]/thread/7COLX6WFFOI3RIOY2IOXWASU3QKAOWKO/, https://lists.fedoraproject.org/archives/list/[email protected]/thread/JNHQI6MDOECJ2HT5GCLEX2DMJFEOWPW7/, https://www.debian.org/lts/security/2021/dla-2629
Affected packages
Package
Name: libebml
Purl: pkg:rpm/mageia/libebml?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
