Bug 1218432 - VUL-0: libebml: MemIOCallback buffer overflows
Summary: VUL-0: libebml: MemIOCallback buffer overflows
Status: NEW
: CVE-2023-52339 (view as bug list)
Alias: None
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Ferdinand Thiessen
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-12-28 16:03 UTC by Carlos López
Modified: 2024-01-12 12:16 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2023-12-28 16:03:12 UTC
Integer overflow bugs when reading and writing via MemIOCallback in libebml.

References:
https://github.com/Matroska-Org/libebml/pull/148
https://github.com/Matroska-Org/libebml/issues/147
Comment 1 Stoyan Manolov 2024-01-12 12:15:31 UTC
OpenSUSE:Factory is already at version 1.4.5. 
OpenSUSE:Backports are affected at version 1.4.4.
Comment 2 Stoyan Manolov 2024-01-12 12:16:10 UTC
*** Bug 1218754 has been marked as a duplicate of this bug. ***