MGASA-2019-0016 - Updated aubio packages fix security vulnerabilities

Publication date: 06 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0016.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2017-17554,
     CVE-2018-14522,
     CVE-2018-14523

NULL pointer dereference in the function aubio_source_avcodec_readframe
which may lead to DoS when playing a crafted audio file (CVE-2017-17554).

A crash in aubio_pitch_set_unit (CVE-2018-14522).

A buffer overrread resulting in crash or information leakage in
new_aubio_pitchyinfft (CVE-2018-14523).

References:
- https://bugs.mageia.org/show_bug.cgi?id=23211
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17554
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14522
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14523

SRPMS:
- 6/core/aubio-0.4.2-2.2.mga6

Mageia 2019-0016: aubio security update

NULL pointer dereference in the function aubio_source_avcodec_readframe which may lead to DoS when playing a crafted audio file (CVE-2017-17554)

Summary

NULL pointer dereference in the function aubio_source_avcodec_readframe which may lead to DoS when playing a crafted audio file (CVE-2017-17554).
A crash in aubio_pitch_set_unit (CVE-2018-14522).
A buffer overrread resulting in crash or information leakage in new_aubio_pitchyinfft (CVE-2018-14523).

References

- https://bugs.mageia.org/show_bug.cgi?id=23211

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17554

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14522

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14523

Resolution

MGASA-2019-0016 - Updated aubio packages fix security vulnerabilities

SRPMS

- 6/core/aubio-0.4.2-2.2.mga6

Severity
Publication date: 06 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0016.html
Type: security
CVE: CVE-2017-17554, CVE-2018-14522, CVE-2018-14523

Related News