Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:2764-1

Опубликовано: 17 авг. 2021
Источник: suse-cvrf

Описание

Security update for libsndfile

This update for libsndfile fixes the following issues:

  • CVE-2018-13139: Fixed a stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. (bsc#1100167)
  • CVE-2018-19432: Fixed a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service. (bsc#1116993)
  • CVE-2021-3246: Fixed a heap buffer overflow vulnerability in msadpcm_decode_block. (bsc#1188540)
  • CVE-2018-19758: Fixed a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service. (bsc#1117954)

Список пакетов

openSUSE Leap 15.3
libsndfile-devel-1.0.28-5.12.1
libsndfile-progs-1.0.28-5.12.1
libsndfile1-1.0.28-5.12.1
libsndfile1-32bit-1.0.28-5.12.1

Описание

A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. The vulnerability can be triggered by the executable sndfile-deinterleave.


Затронутые продукты
openSUSE Leap 15.3:libsndfile-devel-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile-progs-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-32bit-1.0.28-5.12.1

Ссылки

Описание

An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.


Затронутые продукты
openSUSE Leap 15.3:libsndfile-devel-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile-progs-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-32bit-1.0.28-5.12.1

Ссылки

Описание

There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.


Затронутые продукты
openSUSE Leap 15.3:libsndfile-devel-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile-progs-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-32bit-1.0.28-5.12.1

Ссылки

Описание

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.


Затронутые продукты
openSUSE Leap 15.3:libsndfile-devel-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile-progs-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-1.0.28-5.12.1
openSUSE Leap 15.3:libsndfile1-32bit-1.0.28-5.12.1

Ссылки
Уязвимость openSUSE-SU-2021:2764-1