libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement.
{ "vanir_signatures": [ { "deprecated": false, "signature_type": "Line", "target": { "file": "src/EbmlElement.cpp" }, "signature_version": "v1", "digest": { "line_hashes": [ "249363715083438192575858934752190846262", "155038823291976621638196136620035079257", "238334458261036264088903847147222440374", "31736025595015518718928095430263371379", "25033995640621007982586328189385965633", "55678892275375892865694476476557895199", "211731725038840399897453304366352057171", "268358844292664959502256022675968497550", "136758609810238464836257810036947271362", "257757031048684473420359714500939234408", "259883402637309694127599617705892046253", "265086569346827360124167159965842451724" ], "threshold": 0.9 }, "id": "CVE-2019-13615-063c719e", "source": "https://github.com/matroska-org/libebml/commit/05beb69ba60acce09f73ed491bb76f332849c3a0" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "src/EbmlElement.cpp", "function": "EbmlElement::FindNextElement" }, "signature_version": "v1", "digest": { "length": 1792.0, "function_hash": "209908443495593110356754806361852486063" }, "id": "CVE-2019-13615-832824af", "source": "https://github.com/matroska-org/libebml/commit/05beb69ba60acce09f73ed491bb76f332849c3a0" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "src/EbmlElement.cpp", "function": "EbmlElement::FindNextElement" }, "signature_version": "v1", "digest": { "length": 1852.0, "function_hash": "121084963314328406384183393807080098377" }, "id": "CVE-2019-13615-ff01e5be", "source": "https://github.com/matroska-org/libebml/commit/b66ca475be967547af9a3784e720fbbacd381be6" } ] }