openSUSE-SU-2021:1166-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1166-1
openSUSE-SU-2021:1166-1
Summary: Security update for libsndfile
Details: This update for libsndfile fixes the following issues: - CVE-2018-13139: Fixed a stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. (bsc#1100167) - CVE-2018-19432: Fixed a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service. (bsc#1116993) - CVE-2021-3246: Fixed a heap buffer overflow vulnerability in msadpcm_decode_block. (bsc#1188540) - CVE-2018-19758: Fixed a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service. (bsc#1117954) This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/VGFWRIIXBFCLA7GINXJUPUD7YVYB5UKO/, https://bugzilla.suse.com/1100167, https://bugzilla.suse.com/1116993, https://bugzilla.suse.com/1117954, https://bugzilla.suse.com/1188540, https://www.suse.com/security/cve/CVE-2018-13139, https://www.suse.com/security/cve/CVE-2018-19432, https://www.suse.com/security/cve/CVE-2018-19758, https://www.suse.com/security/cve/CVE-2021-3246
Affected packages
Package
Name: libsndfile
Purl: pkg:rpm/opensuse/libsndfile&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
