CVE-2015-8791

medium

Description

The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access.

References

https://github.com/Matroska-Org/libebml/commit/24e5cd7c666b1ddd85619d60486db0a5481c1b90

https://github.com/Matroska-Org/libebml/blob/release-1.3.3/ChangeLog

http://www.debian.org/security/2016/dsa-3538

http://lists.opensuse.org/opensuse-updates/2016-01/msg00035.html

http://lists.matroska.org/pipermail/matroska-users/2015-October/006985.html

Details

Source: Mitre, NVD

Published: 2016-01-29

Updated: 2016-12-03

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Severity: Medium