CVE-2023-52339Integer Overflow or Wraparound in Libebml

Severity
6.5MEDIUMNVD
EPSS
0.3%
top 48.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 12

Description

In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in buffer overflows.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDmatroska/libebml< 1.4.5
Debianmatroska/libebml< 1.4.2-1+deb11u1+3

Patches

🔴Vulnerability Details

3
CVEList
CVE-2023-52339: In libebml before 12024-01-12
GHSA
GHSA-vmjp-26xc-5h39: In libebml before 12024-01-12
OSV
CVE-2023-52339: In libebml before 12024-01-12

📋Vendor Advisories

1
Debian
CVE-2023-52339: libebml - In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when...2023
CVE-2023-52339 — Integer Overflow or Wraparound | cvebase