SUSE-SU-2023:3097-1
Dashboard / Vulnerabilities / SUSE-SU-2023:3097-1
SUSE-SU-2023:3097-1
Published: 1 Aug 2023Last Modified: 1 Aug 2023
Summary: Security update for pipewire
Details: This update for pipewire fixes the following security issues: - Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682). Bugfixes: - Fixed division by 0 and other issues with invalid values (glfo#pipewire/pipewire#2953) - Fixed an overflow resulting in choppy sound in some cases (glfo#pipewire/pipewire#2680)
References: https://www.suse.com/support/update/announcement/2023/suse-su-20233097-1/, https://bugzilla.suse.com/1213682
Affected packages
Package
Name: pipewire
Purl: pkg:rpm/suse/pipewire&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -0.3.6-150200.3.9.1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
