First published: Tue Jun 30 2020(Updated: )
In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MediaArea MediaInfo | =20.03 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15395 is a vulnerability in MediaInfoLib in MediaArea MediaInfo 20.03, which allows for a stack-based buffer over-read in the MpegPs parsing.
CVE-2020-15395 has a severity rating of 7.8 (high).
CVE-2020-15395 affects MediaArea MediaInfo version 20.03, allowing for a stack-based buffer over-read.
CVE-2020-15395 impacts Fedora 32 as it includes the affected version of MediaArea MediaInfo.
CVE-2020-15395 can be fixed by updating MediaArea MediaInfo to a version that addresses the vulnerability.