Candidate: CVE-2015-8792 PublicDate: 2016-01-29 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8792 https://github.com/Matroska-Org/libmatroska/commit/0a2d3e3644a7453b6513db2f9bc270f77943573f https://github.com/Matroska-Org/libmatroska/blob/release-1.4.4/ChangeLog http://lists.opensuse.org/opensuse-updates/2016-01/msg00035.html http://lists.matroska.org/pipermail/matroska-users/2015-October/006985.html Description: The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process heap memory via crafted EBML lacing, which triggers an invalid memory access. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N [5.3 MEDIUM] Patches_libmatroska: upstream_libmatroska: released (1.4.4) precise_libmatroska: ignored (reached end-of-life) precise/esm_libmatroska: DNE (precise was needed) trusty_libmatroska: released (1.4.1-2+deb8u1build0.14.04.1) trusty/esm_libmatroska: DNE (trusty was released [1.4.1-2+deb8u1build0.14.04.1]) vivid_libmatroska: ignored (reached end-of-life) vivid/stable-phone-overlay_libmatroska: DNE vivid/ubuntu-core_libmatroska: DNE wily_libmatroska: ignored (reached end-of-life) xenial_libmatroska: not-affected (1.4.4-1) yakkety_libmatroska: not-affected (1.4.4-1) zesty_libmatroska: not-affected (1.4.4-1) devel_libmatroska: not-affected (1.4.4-1)