SUSE-SU-2017:1182-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1182-1
SUSE-SU-2017:1182-1
Summary: Security update for audiofile
Details: This update for audiofile fixes the following issues: Security issues fixed: - CVE-2017-6827: heap-based buffer overflow in MSADPCM::initializeCoefficients (MSADPCM.cpp) (bsc#1026979) - CVE-2017-6828: heap-based buffer overflow in readValue (FileHandle.cpp) (bsc#1026980) - CVE-2017-6829: global buffer overflow in decodeSample (IMA.cpp) (bsc#1026981) - CVE-2017-6830: heap-based buffer overflow in alaw2linear_buf (G711.cpp) (bsc#1026982) - CVE-2017-6831: heap-based buffer overflow in IMA::decodeBlockWAVE (IMA.cpp) (bsc#1026983) - CVE-2017-6832: heap-based buffer overflow in MSADPCM::decodeBlock (MSADPCM.cpp) (bsc#1026984) - CVE-2017-6833: divide-by-zero in BlockCodec::runPull (BlockCodec.cpp) (bsc#1026985) - CVE-2017-6834: heap-based buffer overflow in ulaw2linear_buf (G711.cpp) (bsc#1026986) - CVE-2017-6835: divide-by-zero in BlockCodec::reset1 (BlockCodec.cpp) (bsc#1026988) - CVE-2017-6836: heap-based buffer overflow in Expand3To4Module::run (SimpleModule.h) (bsc#1026987) - CVE-2017-6837, CVE-2017-6838, CVE-2017-6839: multiple ubsan crashes (bsc#1026978)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171182-1/, https://bugzilla.suse.com/1026978, https://bugzilla.suse.com/1026979, https://bugzilla.suse.com/1026980, https://bugzilla.suse.com/1026981, https://bugzilla.suse.com/1026982, https://bugzilla.suse.com/1026983, https://bugzilla.suse.com/1026984, https://bugzilla.suse.com/1026985, https://bugzilla.suse.com/1026986, https://bugzilla.suse.com/1026987, https://bugzilla.suse.com/1026988, https://www.suse.com/security/cve/CVE-2017-6827, https://www.suse.com/security/cve/CVE-2017-6828, https://www.suse.com/security/cve/CVE-2017-6829, https://www.suse.com/security/cve/CVE-2017-6830, https://www.suse.com/security/cve/CVE-2017-6831, https://www.suse.com/security/cve/CVE-2017-6832, https://www.suse.com/security/cve/CVE-2017-6833, https://www.suse.com/security/cve/CVE-2017-6834, https://www.suse.com/security/cve/CVE-2017-6835, https://www.suse.com/security/cve/CVE-2017-6836, https://www.suse.com/security/cve/CVE-2017-6837, https://www.suse.com/security/cve/CVE-2017-6838, https://www.suse.com/security/cve/CVE-2017-6839
Affected packages
Package
Name: audiofile
Purl: pkg:rpm/suse/audiofile&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
