openSUSE-SU-2021:2764-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:2764-1
openSUSE-SU-2021:2764-1
Summary: Security update for libsndfile
Details: This update for libsndfile fixes the following issues: - CVE-2018-13139: Fixed a stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. (bsc#1100167) - CVE-2018-19432: Fixed a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service. (bsc#1116993) - CVE-2021-3246: Fixed a heap buffer overflow vulnerability in msadpcm_decode_block. (bsc#1188540) - CVE-2018-19758: Fixed a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service. (bsc#1117954)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/Y7PPP2MGW6YG46U25HVAXKQBMB2PV4XV/, https://bugzilla.suse.com/1100167, https://bugzilla.suse.com/1116993, https://bugzilla.suse.com/1117954, https://bugzilla.suse.com/1188540, https://www.suse.com/security/cve/CVE-2018-13139, https://www.suse.com/security/cve/CVE-2018-19432, https://www.suse.com/security/cve/CVE-2018-19758, https://www.suse.com/security/cve/CVE-2021-3246
Affected packages
Package
Name: libsndfile
Purl: pkg:rpm/opensuse/libsndfile&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
