Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:0017-1

Опубликовано: 04 янв. 2021
Источник: suse-cvrf

Описание

Security update for flac

This update for flac fixes the following issues:

  • CVE-2020-0499: Fixed an out-of-bounds access (bsc#1180099).

Список пакетов

HPE Helion OpenStack 8
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Enterprise Storage 5
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-BCL
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server 12 SP3-BCL
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server 12 SP3-LTSS
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server 12 SP4-LTSS
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server 12 SP5
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE Linux Enterprise Software Development Kit 12 SP5
flac-devel-1.3.0-12.3.1
SUSE Linux Enterprise Workstation Extension 12 SP5
libFLAC++6-32bit-1.3.0-12.3.1
SUSE OpenStack Cloud 7
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE OpenStack Cloud 8
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE OpenStack Cloud 9
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE OpenStack Cloud Crowbar 8
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1
SUSE OpenStack Cloud Crowbar 9
libFLAC++6-1.3.0-12.3.1
libFLAC8-1.3.0-12.3.1
libFLAC8-32bit-1.3.0-12.3.1

Описание

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070


Затронутые продукты
HPE Helion OpenStack 8:libFLAC++6-1.3.0-12.3.1
HPE Helion OpenStack 8:libFLAC8-1.3.0-12.3.1
HPE Helion OpenStack 8:libFLAC8-32bit-1.3.0-12.3.1
SUSE Enterprise Storage 5:libFLAC++6-1.3.0-12.3.1

Ссылки
Уязвимость SUSE-SU-2021:0017-1