A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.
{ "binaries": [ { "binary_name": "mkvtoolnix", "binary_version": "8.8.0-1" }, { "binary_name": "mkvtoolnix-gui", "binary_version": "8.8.0-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-4022.json"
{ "binaries": [ { "binary_name": "mkvtoolnix", "binary_version": "19.0.0-1" }, { "binary_name": "mkvtoolnix-gui", "binary_version": "19.0.0-1" } ] }
{ "binaries": [ { "binary_name": "mkvtoolnix", "binary_version": "45.0.0-2" }, { "binary_name": "mkvtoolnix-gui", "binary_version": "45.0.0-2" } ] }
{ "binaries": [ { "binary_name": "mkvtoolnix", "binary_version": "65.0.0-1" }, { "binary_name": "mkvtoolnix-gui", "binary_version": "65.0.0-1" } ] }
{ "binaries": [ { "binary_name": "mkvtoolnix", "binary_version": "82.0-1build2" }, { "binary_name": "mkvtoolnix-gui", "binary_version": "82.0-1build2" } ] }
{ "binaries": [ { "binary_name": "mkvtoolnix", "binary_version": "94.0-1" }, { "binary_name": "mkvtoolnix-gui", "binary_version": "94.0-1" } ] }
{ "binaries": [ { "binary_name": "mkvtoolnix", "binary_version": "97.0-1build1" }, { "binary_name": "mkvtoolnix-gui", "binary_version": "97.0-1build1" } ] }