ArchLinux: 201902-8: aubio: denial of service
Summary
- CVE-2018-19800 (denial of service)
A potential buffer overflow vulnerability was found on invalid
new_aubio-tempo in aubio before 0.4.9, which may lead to application
crash when playing a crafted audio file.
- CVE-2018-19801 (denial of service)
A NULL pointer dereference (denial of service) vulnerability was found
on invalid n_filters in aubio before 0.4.9, which may lead to
application crash when playing a crafted audio file.
- CVE-2018-19802 (denial of service)
A NULL pointer dereference (denial of service) vulnerability was found
on invalid new_aubio_onset in aubio before 0.4.9, which may lead to
application crash when playing a crafted audio file.
Resolution
Upgrade to 0.4.9-1.
# pacman -Syu "aubio>=0.4.9-1"
The problems have been fixed upstream in version 0.4.9.
References
https://github.com/aubio/aubio/blob/0.4.9/ChangeLog#L14-L17 https://github.com/aubio/aubio/commit/1cf031a3a5b869368562b1251419fd45191eaa53 https://github.com/aubio/aubio/commit/bcc53876548334b4c5f1ebd47a5bd5f151974e8b https://github.com/aubio/aubio/commit/c5ee1307bdc004e43302abeca1802c2692b33a8e https://security.archlinux.org/CVE-2018-19800 https://security.archlinux.org/CVE-2018-19801 https://security.archlinux.org/CVE-2018-19802
Workaround
None.