Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41 libxmp Security Advisory: Critical Memory Threats Fixed

fedora
Calendar Grey January 11, 2025
Dist Fedora Esm H88
The Libxmp toolkit in Fedora 41 has undergone essential upgrades that resolve significant memory vulnerabilities and buffer overrun concerns.
Latest upstream release

Summary

Libxmp is a library that renders module files to PCM data. It supports

over 90 mainstream and obscure module formats including Protracker (MOD),

Scream Tracker 3 (S3M), Fast Tracker II (XM), and Impulse Tracker (IT).

Many compressed module formats are supported, including popular Unix, DOS,

and Amiga file packers including gzip, bzip2, SQSH, Powerpack, etc.

Update Information:

Latest upstream release. Changelog: Fixes: CVE-2023-45679: Attempt to free an uninitialized memory pointer in vorbis_deinit() CVE-2023-45680: Null pointer dereference in vorbis_deinit() CVE-2023-45681: Out of bounds heap buffer write CVE-2023-45676: Multi-byte write heap buffer overflow in start_decoder() CVE-2023-45677: Heap buffer out of bounds write in start_decoder() CVE-2023-45682: Wild address read in vorbis_decode_packet_rest()

Change Log

* Thu Jan 2 2025 Dominik Mierzejewski - 4.6.1-1 - update to 4.6.1 (rhbz#2335113) - enumerate source licenses and correct License tag * Mon Sep 2 2024 Miroslav Suchý - 4.6.0-6 - convert license to SPDX

References


[ 1 ] Bug #2335113 - libxmp-4.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2335113

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-23e4aeeb91' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: libxmp
Product: Fedora 41
Version: 4.6.1
Release: 2.fc41
URL:
Summary: A multi-format module playback library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here