Bug 25155 - libebml new security issue CVE-2019-13615
Summary: libebml new security issue CVE-2019-13615
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Shlomi Fish
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-07-20 00:54 CEST by Marc Krämer
Modified: 2019-11-06 21:26 CET (History)
3 users (show)

See Also:
Source RPM: libebml-1.3.4-1.mga6.src.rpm
CVE:
Status comment: Fixed upstream in 1.3.6


Attachments

Description Marc Krämer 2019-07-20 00:54:44 CEST
There is no fix yet, but we should ship it when it is ready
https://trac.videolan.org/vlc/ticket/22474
https://nvd.nist.gov/vuln/detail/CVE-2019-13615
Marc Krämer 2019-07-20 00:54:55 CEST

Whiteboard: (none) => MGA6TOO

Jani Välimaa 2019-07-20 15:22:18 CEST

QA Contact: (none) => security
Component: RPM Packages => Security

David Walser 2019-07-20 15:55:13 CEST

Assignee: bugsquad => shlomif
Summary: Critical security issue in vlc => vlc new security issue CVE-2019-13615

Comment 1 psyca 2019-07-24 20:53:16 CEST
Looks like invalid report in VLC Bugtracker.
Please recheck.

CC: (none) => linux

Comment 2 Marc Krämer 2019-07-24 21:18:08 CEST
if we have a newer libebml in mga6 and mga7 which we link to, I agree. Unfortunately they don't say which version is vulunerable.
Sorry, for the noise, it was announced in the local it press not to use vlc.
Comment 3 katnatek 2019-07-24 22:32:51 CEST
From https://trac.videolan.org/vlc/ticket/22474#comment:21

"Issue is too old libebml in Ubuntu 18.04: libebml 1.3.6 fixes this issue. End of story: VLC is not vulnerable, whether this is 3.0.7.1 or even 3.0.4. The issue is in a 3rd party library, and it was fixed in VLC binaries version 3.0.3, out more than one year ago... "

In Mageia 7 we have 1.3.7, but in Mageia 6 we have 1.3.4, not sure if that version is vulnerable.
David Walser 2019-07-25 03:30:44 CEST

Whiteboard: MGA6TOO => (none)
Summary: vlc new security issue CVE-2019-13615 => libebml new security issue CVE-2019-13615
Version: 7 => 6
Source RPM: vlc-3.0.7.1-1.mga7.src.rpm => libebml-1.3.4-1.mga6.src.rpm

Comment 4 David Walser 2019-08-12 01:15:36 CEST
Ubuntu has issued an advisory for this on July 25:
https://usn.ubuntu.com/4073-1/

Status comment: (none) => Fixed upstream in 1.3.6
CC: (none) => luigiwalser

Comment 5 Mike Rambo 2019-11-06 21:26:47 CET
Mageia 6 is EOL.

CC: (none) => mrambo
Status: NEW => RESOLVED
Resolution: (none) => OLD


Note You need to log in before you can comment on or make changes to this bug.