Debian Security Advisory

DLA-2603-1 libmediainfo -- LTS security update

Date Reported:
23 Mar 2021
Affected Packages:
libmediainfo
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-11372, CVE-2019-11373, CVE-2020-15395, CVE-2020-26797.
More information:

It was discovered that there were a number of vulnerabilities in libmediainfo, a library reading metadata such as track names, lengths, etc. from media files.

  • CVE-2019-11372

    An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.

  • CVE-2019-11373

    An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.

  • CVE-2020-15395

    In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).

  • CVE-2020-26797

    Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.

For Debian 9 Stretch, these problems have been fixed in version 0.7.91-1+deb9u1.

We recommend that you upgrade your libmediainfo packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS