CVE-2021-3405: Medium severity Matroska Libebml vulnerability
Published Feb 23, 2021
·Updated
A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml.
Affected Software
5 affected components
Matroska Libebml<1.4.2
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Debian Debian Linux=9.0
Event History
Feb 23, 2021
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-3405?
CVE-2021-3405 is classified as a high severity vulnerability due to the potential for heap overflow exploit.
2
How do I fix CVE-2021-3405?
To fix CVE-2021-3405, upgrade libebml to version 1.4.2 or later.
3
What systems are affected by CVE-2021-3405?
CVE-2021-3405 affects libebml versions prior to 1.4.2, as well as specific versions of Fedora and Debian.
4
What types of attacks can be executed using CVE-2021-3405?
Exploitation of CVE-2021-3405 could lead to remote code execution or application crashes through crafted input.
5
Who reported CVE-2021-3405 and when?
CVE-2021-3405 was reported in April 2021 as a security issue in the libebml library.