Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 27 FEDORA-2018-d6002f761d Critical WavPack Buffer Overflow

fedora
Calendar Grey May 26, 2018
Dist Fedora Esm H88
Recent Fedora patch addresses several vulnerabilities in WavPack that impact sound file compression. It's advised to apply the necessary updates immediately.
Security fix for CVE-2018-10536 CVE-2018-10537 CVE-2018-10538 CVE-2018-10539 CVE-2018-10540

Summary

WavPack is a completely open audio compression format providing lossless,

high-quality lossy, and a unique hybrid compression mode. Although the

technology is loosely based on previous versions of WavPack, the new

version 4 format has been designed from the ground up to offer unparalleled

performance and functionality.

Security fix for CVE-2018-10536 CVE-2018-10537 CVE-2018-10538 CVE-2018-10539

CVE-2018-10540

* Tue May 22 2018 Miroslav Lichvar - 5.1.0-8

- Fix for CVE-2018-10536, CVE-2018-10537, CVE-2018-10538, CVE-2018-10539,

CVE-2018-10540

* Tue Feb 20 2018 Peter Lemenkov - 5.1.0-7

- Fix for CVE-2018-6767, CVE-2018-7253, and two more GH issues

* Fri Feb 9 2018 Fedora Release Engineering - 5.1.0-6

- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

* Sat Feb 3 2018 Igor Gnatenko - 5.1.0-5

- Switch to %ldconfig_scriptlets

[ 1 ] Bug #1574719 - CVE-2018-10536 wavpack: out of bounds write in ParseRiffHeaderConfig in riff.c

https://bugzilla.redhat.com/show_bug.cgi?id=1574719

[ 2 ] Bug #1574726 - CVE-2018-10537 wavpack: out of bounds write in ParseWave64HeaderConfig in wave64.c

https://bugzilla.redhat.com/show_bug.cgi?id=1574726

[ 3 ] Bug #1574728 - CVE-2018-10538 wavpack: out of bounds write in ParseRiffHeaderConfig in riff.c

https://bugzilla.redhat.com/show_bug.cgi?id=1574728

[ 4 ] Bug #1574729 - CVE-2018-10539 wavpack: out of bounds write in ParseDsdiffHeaderConfig in dsdiff.c

https://bugzilla.redhat.com/show_bug.cgi?id=1574729

[ 5 ] Bug #1574731 - CVE-2018-10540 wavpack: out of bounds write in ParseWave64HeaderConfig in wave64.c

https://bugzilla.redhat.com/show_bug.cgi?id=1574731

su -c 'dnf upgrade --advisory FEDORA-2018-d6002f761d' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V4OI47KC2PI4JA7JHKSCIXDK75437ZO3/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 5.1.0
Release: 8.fc27
Summary: A completely open audiocodec

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here