ALSA-2019:3703
Dashboard / Vulnerabilities / ALSA-2019:3703
Summary: Low: libvorbis security update
Details: The libvorbis package contains runtime libraries for use in programs that support Ogg Vorbis, a fully open, non-proprietary, patent- and royalty-free, general-purpose compressed format for audio and music at fixed and variable bitrates. Security Fix(es): * libvorbis: heap buffer overflow in mapping0_forward function (CVE-2018-10392) * libvorbis: stack buffer overflow in bark_noise_hybridmp function (CVE-2018-10393) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://errata.almalinux.org/8/ALSA-2019-3703.html, https://vulners.com/cve/CVE-2018-10392, https://vulners.com/cve/CVE-2018-10393
Affected packages
Package
Name: libvorbis
Purl: pkg:rpm/almalinux/libvorbis
Affected ranges
Type: ECOSYSTEM
Events:
