Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2019:3703

Опубликовано: 05 нояб. 2019
Источник: rocky
Оценка: Low

Описание

Low: libvorbis security update

The libvorbis package contains runtime libraries for use in programs that support Ogg Vorbis, a fully open, non-proprietary, patent- and royalty-free, general-purpose compressed format for audio and music at fixed and variable bitrates.

Security Fix(es):

  • libvorbis: heap buffer overflow in mapping0_forward function (CVE-2018-10392)

  • libvorbis: stack buffer overflow in bark_noise_hybridmp function (CVE-2018-10393)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libvorbisx86_642.el8libvorbis-1.3.6-2.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
больше 5 лет назад

ELSA-2019-3703: libvorbis security update (LOW)

CVSS3: 7.5
ubuntu
около 7 лет назад

bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.

CVSS3: 7.3
redhat
около 7 лет назад

bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.

CVSS3: 7.5
nvd
около 7 лет назад

bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.

CVSS3: 7.5
debian
около 7 лет назад

bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-b ...