Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-5922

[ GLSA 201811-23 ] libsndfile: Multiple vulnerabilities

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Fixed Earlier
    • Icon: Normal Normal
    • None
    • None
    • None

      Synopsis
      ========

      Multiple vulnerabilities have been found in libsndfile, the worst of
      which might allow remote attackers to cause a Denial of Service
      condition.

      Background
      ==========

      libsndfile is a C library for reading and writing files containing
      sampled sound.

      Affected packages
      =================

      -------------------------------------------------------------------
      Package / Vulnerable / Unaffected
      -------------------------------------------------------------------
      1 media-libs/libsndfile < 1.0.28-r4 >= 1.0.28-r4

      Description
      ===========

      Multiple vulnerabilities have been discovered in libsndfile. Please
      review the CVE identifiers referenced below for details.

      Impact
      ======

      A remote attacker, by enticing a user to open a specially crafted file,
      could cause a Denial of Service condition or have other unspecified
      impacts.

      Workaround
      ==========

      There is no known workaround at this time.

      Resolution
      ==========

      All libsndfile users should upgrade to the latest version:

      1. emerge --sync
      2. emerge --ask --oneshot -v ">=media-libs/libsndfile-1.0.28-r4"

      References
      ==========

      [ 1 ] CVE-2017-12562
      https://nvd.nist.gov/vuln/detail/CVE-2017-12562
      [ 2 ] CVE-2017-14634
      https://nvd.nist.gov/vuln/detail/CVE-2017-14634
      [ 3 ] CVE-2017-6892
      https://nvd.nist.gov/vuln/detail/CVE-2017-6892
      [ 4 ] CVE-2017-8361
      https://nvd.nist.gov/vuln/detail/CVE-2017-8361
      [ 5 ] CVE-2017-8362
      https://nvd.nist.gov/vuln/detail/CVE-2017-8362
      [ 6 ] CVE-2017-8363
      https://nvd.nist.gov/vuln/detail/CVE-2017-8363
      [ 7 ] CVE-2017-8365
      https://nvd.nist.gov/vuln/detail/CVE-2017-8365
      [ 8 ] CVE-2018-13139
      https://nvd.nist.gov/vuln/detail/CVE-2018-13139

      Availability
      ============

      This GLSA and any updates to it are available for viewing at
      the Gentoo Security Website:

      https://security.gentoo.org/glsa/201811-23

            oleg oleg
            palica Pavol Cupka
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: