The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid memory access.
{ "binaries": [ { "binary_name": "libebml-dev", "binary_version": "1.3.0-2+deb8u1build0.14.04.1" }, { "binary_name": "libebml4", "binary_version": "1.3.0-2+deb8u1build0.14.04.1" } ], "availability": "No subscription required" }