Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 32: 2021-4e40ccb5e6 Critical Update: Libmysofa Input Errors

fedora
Calendar Grey February 25, 2021
Dist Fedora Esm H88
Patch resolves vulnerabilities in libmyapp. Urgent fixes for Fedora 34 targeting data processing flaws.
Fixes various security issues by upgrading to the current 1.2 version.

Summary

This is a simple set of C functions to read AES SOFA files, if they

contain HRTFs stored according to the AES69-2015 standard.

Fixes various security issues by upgrading to the current 1.2 version.

* Mon Feb 8 2021 Nicolas Chauvet - 1.2-4

- Update to 1.2

* Tue Jan 26 2021 Fedora Release Engineering - 1.1-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

* Sat Aug 1 2020 Fedora Release Engineering - 1.1-3

- Second attempt - Rebuilt for

https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

* Tue Jul 28 2020 Fedora Release Engineering - 1.1-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild

[ 1 ] Bug #1928824 - CVE-2020-36152 libmysofa: Buffer overflow in readDataVar in hdf/dataobject.c [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928824

[ 2 ] Bug #1928825 - CVE-2020-36152 libmysofa: Buffer overflow in readDataVar in hdf/dataobject.c [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928825

[ 3 ] Bug #1928826 - CVE-2020-36151 libmysofa: Incorrect handling of input data in mysofa_resampler_reset_mem function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928826

[ 4 ] Bug #1928827 - CVE-2020-36151 libmysofa: Incorrect handling of input data in mysofa_resampler_reset_mem function [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928827

[ 5 ] Bug #1928829 - CVE-2020-36150 libmysofa: Incorrect handling of input data in loudness function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928829

[ 6 ] Bug #1928830 - CVE-2020-36150 libmysofa: Incorrect handling of input data in loudness function [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928830

[ 7 ] Bug #1928833 - CVE-2020-36148 libmysofa: Incorrect handling of input data in verifyAttribute function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928833

[ 8 ] Bug #1928834 - CVE-2020-36148 libmysofa: Incorrect handling of input data in verifyAttribute function [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928834

[ 9 ] Bug #1928835 - CVE-2020-36149 libmysofa: Incorrect handling of input data in changeAttribute function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928835

[ 10 ] Bug #1928836 - CVE-2020-36149 libmysofa: Incorrect handling of input data in changeAttribute function [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1928836

su -c 'dnf upgrade --advisory FEDORA-2021-4e40ccb5e6' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 1.2
Release: 4.fc32
Summary: C functions for reading HRTFs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here