Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia: Important Security Update 2019-0016 for Aubio Null Pointer DoS

mageia
Calendar Grey January 6, 2019
Dist Mageia Esm H88
Recent security updates addressing aubio vulnerabilities in Mageia mitigate risks associated with potential crashes and denial-of-service (DoS) threats.
NULL pointer dereference in the function aubio_source_avcodec_readframe which may lead to DoS when playing a crafted audio file (CVE-2017-17554)

Summary

NULL pointer dereference in the function aubio_source_avcodec_readframe which may lead to DoS when playing a crafted audio file (CVE-2017-17554).
A crash in aubio_pitch_set_unit (CVE-2018-14522).
A buffer overrread resulting in crash or information leakage in new_aubio_pitchyinfft (CVE-2018-14523).

References

- https://bugs.mageia.org/show_bug.cgi?id=23211

- - https://www.cve.org/CVERecord?id=CVE-2017-17554

- https://www.cve.org/CVERecord?id=CVE-2018-14522

- https://www.cve.org/CVERecord?id=CVE-2018-14523

Resolution

SRPMS

- 6/core/aubio-0.4.2-2.2.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 06 Jan 2019
URL: https://advisories.mageia.org/MGASA-2019-0016.html
Type: security
CVE: CVE-2017-17554, CVE-2018-14522, CVE-2018-14523

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here