ALT-PU-2016-1932-1
Package libmatroska updated to version 1.4.5-alt1 for branch sisyphus in task 169101.
Closed vulnerabilities
Published: 2016-01-29
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2015-8792
The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process heap memory via crafted EBML lacing, which triggers an invalid memory access.
Severity: MEDIUM (5.3)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
References:
- [matroska-users] 20151020 libEBML v1.3.3, libMatroska v1.4.4 released: important fixes
- [matroska-users] 20151020 libEBML v1.3.3, libMatroska v1.4.4 released: important fixes
- openSUSE-SU-2016:0125
- openSUSE-SU-2016:0125
- DSA-3526
- DSA-3526
- https://github.com/Matroska-Org/libmatroska/blob/release-1.4.4/ChangeLog
- https://github.com/Matroska-Org/libmatroska/blob/release-1.4.4/ChangeLog
- https://github.com/Matroska-Org/libmatroska/commit/0a2d3e3644a7453b6513db2f9bc270f77943573f
- https://github.com/Matroska-Org/libmatroska/commit/0a2d3e3644a7453b6513db2f9bc270f77943573f