Debian Security Advisory
DLA-2603-1 libmediainfo -- LTS security update
- Date Reported:
- 23 Mar 2021
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2019-11372, CVE-2019-11373, CVE-2020-15395, CVE-2020-26797.
- More information:
It was discovered that there were a number of vulnerabilities in libmediainfo, a library reading metadata such as track names, lengths, etc. from media files.
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).
Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.
For Debian 9
Stretch, these problems have been fixed in version 0.7.91-1+deb9u1.
We recommend that you upgrade your libmediainfo packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS