libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe... I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end use…
https://security-tracker.debian.org/tracker/CVE-2019-13615
In this case, this hasn't yet been updated with the info from the VLC team, I expect it'll be marked ignore or not-vulnerable once that happens.
I don't know the real CVE for the libebml issue but it doesn't appear to be listed at https://security-tracker.debian.org/tracker/source-package/l... which means that the Debian security team aren't aware of it.