Описание
Security update for libsndfile
This update for libsndfile fixes the following issues:
- CVE-2018-13139: Fixed a stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. (bsc#1100167)
- CVE-2018-19432: Fixed a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service. (bsc#1116993)
- CVE-2021-3246: Fixed a heap buffer overflow vulnerability in msadpcm_decode_block. (bsc#1188540)
- CVE-2018-19758: Fixed a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service. (bsc#1117954)
Список пакетов
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 9
Ссылки
- Link for SUSE-SU-2021:2615-1
- E-Mail link for SUSE-SU-2021:2615-1
- SUSE Security Ratings
- SUSE Bug 1100167
- SUSE Bug 1116993
- SUSE Bug 1117954
- SUSE Bug 1188540
- SUSE CVE CVE-2018-13139 page
- SUSE CVE CVE-2018-19432 page
- SUSE CVE CVE-2018-19758 page
- SUSE CVE CVE-2021-3246 page
Описание
A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. The vulnerability can be triggered by the executable sndfile-deinterleave.
Затронутые продукты
Ссылки
- CVE-2018-13139
- SUSE Bug 1100167
- SUSE Bug 1116993
- SUSE Bug 1211493
Описание
An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.
Затронутые продукты
Ссылки
- CVE-2018-19432
- SUSE Bug 1116993
Описание
There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.
Затронутые продукты
Ссылки
- CVE-2018-19758
- SUSE Bug 1117954
- SUSE Bug 1125575
Описание
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
Затронутые продукты
Ссылки
- CVE-2021-3246
- SUSE Bug 1188540