Описание
Security update for libsndfile
This update for libsndfile fixes the following issues:
- CVE-2022-33065: Fixed an integer overflow that could cause memory safety issues when reading a MAT4 file (bsc#1213451).
Список пакетов
SUSE Linux Enterprise Server 12 SP5
libsndfile1-1.0.25-36.29.1
libsndfile1-32bit-1.0.25-36.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libsndfile1-1.0.25-36.29.1
libsndfile1-32bit-1.0.25-36.29.1
SUSE Linux Enterprise Software Development Kit 12 SP5
libsndfile-devel-1.0.25-36.29.1
Ссылки
- Link for SUSE-SU-2023:4331-1
- E-Mail link for SUSE-SU-2023:4331-1
- SUSE Security Ratings
- SUSE Bug 1213451
- SUSE CVE CVE-2022-33065 page
Описание
Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.
Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libsndfile1-1.0.25-36.29.1
SUSE Linux Enterprise Server 12 SP5:libsndfile1-32bit-1.0.25-36.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:libsndfile1-1.0.25-36.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:libsndfile1-32bit-1.0.25-36.29.1
Ссылки
- CVE-2022-33065
- SUSE Bug 1213451
- SUSE Bug 1217517
- SUSE Bug 1217558
- SUSE Bug 1217605