MGASA-2020-0045 - Updated sox packages fix security vulnerabilities

Publication date: 22 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0045.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-8354,
     CVE-2019-8355,
     CVE-2019-8356,
     CVE-2019-8357

Updated sox packages fix security vulnerabilities:

It was discovered that SoX incorrectly handled certain MP3 files. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2019-8354, CVE-2019-8355, CVE-2019-8356, CVE-2019-8357)

References:
- https://bugs.mageia.org/show_bug.cgi?id=25289
- https://sourceforge.net/p/sox/bugs/319/
- https://sourceforge.net/p/sox/bugs/320/
- https://sourceforge.net/p/sox/bugs/321/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8354
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8355
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8356
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8357

SRPMS:
- 7/core/sox-14.4.3-0.git20200117.1.mga7

Mageia 2020-0045: sox security update

Updated sox packages fix security vulnerabilities: It was discovered that SoX incorrectly handled certain MP3 files

Summary

Updated sox packages fix security vulnerabilities:
It was discovered that SoX incorrectly handled certain MP3 files. An attacker could possibly use this issue to cause a denial of service. (CVE-2019-8354, CVE-2019-8355, CVE-2019-8356, CVE-2019-8357)

References

- https://bugs.mageia.org/show_bug.cgi?id=25289

- https://sourceforge.net/p/sox/bugs/319/

- https://sourceforge.net/p/sox/bugs/320/

- https://sourceforge.net/p/sox/bugs/321/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8354

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8355

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8356

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8357

Resolution

MGASA-2020-0045 - Updated sox packages fix security vulnerabilities

SRPMS

- 7/core/sox-14.4.3-0.git20200117.1.mga7

Severity
Publication date: 22 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0045.html
Type: security
CVE: CVE-2019-8354, CVE-2019-8355, CVE-2019-8356, CVE-2019-8357

Related News