Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 605548 - dev-libs/libebml: two vulnerabilities
Summary: dev-libs/libebml: two vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-01-13 09:05 UTC by Agostino Sarubbo
Modified: 2018-04-12 02:35 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-01-13 09:05:02 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=1412632:

A vulnerability was found in libebml. A use after free/double free vulnerability can occur in libebml while parsing Track elements of the MKV container 
which would crash the application.

References:
http://www.talosintelligence.com/reports/TALOS-2016-0037/


From https://bugzilla.redhat.com/show_bug.cgi?id=1412629:

A vulnerability was found in libebml. A specially crafted unicode string can cause an off-by-few read on the heap in unicode string parsing code in 
libebml. This issue can potentially be used for information leaks.

References:
http://www.talosintelligence.com/reports/TALOS-2016-0036/


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Michael Boyle 2017-06-16 03:23:27 UTC
@maintainers, Has this been stabilized?  Can this be sent to glsa?


Mike Boyle
Gentoo Security Padawan
Comment 2 Pacho Ramos gentoo-dev 2017-09-08 13:07:51 UTC
Per https://bugzilla.redhat.com/show_bug.cgi?id=1303861 , this was fixed in anything newer than 1.3.3... and we have 1.3.4 and 1.3.5 in the tree
Comment 3 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2018-04-12 02:35:00 UTC
Downgrading to B3 since it's a DoS vulnerability.

Tree clean.

GLSA Vote: No