Bug ID 1173630
Summary VUL-0: CVE-2020-15395: libmediainfo, mediainfo: buffer overflow in the MpegPs parser
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.1
Hardware Other
URL https://smash.suse.de/issue/262592/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee aloisio@gmx.com
Reporter wolfgang.frisch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2020-15395

In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer
over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an
off-by-one during MpegPs parsing).

References:
https://sourceforge.net/p/mediainfo/bugs/1127/
https://bugzilla.redhat.com/show_bug.cgi?id=1852956
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15395
http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-15395.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15395
https://mediaarea.net/en/MediaInfo


You are receiving this mail because: