Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 37: FEDORA-2023-e23e432cb2 Critical Audiofile Memory Leak

fedora
Calendar Grey November 22, 2023
Dist Fedora Esm H88
The latest Fedora 37 updates tackle vulnerabilities found in audiofile. Find details on the patch related to CVE-2022-24599 here.
Patch for CVE-2022-24599

Summary

The Audio File library is an implementation of the Audio File Library

from SGI, which provides an API for accessing audio file formats like

AIFF/AIFF-C, WAVE, and NeXT/Sun .snd/.au files. This library is used

by the EsounD daemon.

Install audiofile if you are installing EsounD or you need an API for

any of the sound file formats it can handle.

Update Information:

Patch for CVE-2022-24599

Change Log

* Mon Nov 13 2023 Gwyn Ciesla - 1:0.3.6-36 Patch for CVE-2022-24599 * Wed Jul 19 2023 Fedora Release Engineering - 1:0.3.6-35 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Mar 2 2023 Gwyn Ciesla - 1:0.3.6-34 - migrated to SPDX license * Wed Jan 18 2023 Fedora Release Engineering - 1:0.3.6-33 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Tue Sep 13 2022 Michel Alexandre Salim - 1:0.3.6-32 - Rebuilt for flac 1.4.0

References


[ 1 ] Bug #2058373 - CVE-2022-24599 audiofile: memory leak in printinfo.c [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2058373

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-e23e432cb2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: audiofile
Product: Fedora 37
Version: 0.3.6
Release: 36.fc37
Summary: Library for accessing various audio file formats

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here