Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 7: 2020-0476 Critical Advisory: Jack2 Double Close Issue and Fix

mageia
Calendar Grey December 29, 2020
Dist Mageia Esm H88
Mageia 2021-1023 resolves a vulnerability found in the OpenSSL component, mitigating risks of data corruption and unauthorized access.
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running

Summary

posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor (CVE-2019-13351).

References

- https://bugs.mageia.org/show_bug.cgi?id=27775

-

- https://www.cve.org/CVERecord?id=CVE-2019-13351

Resolution

SRPMS

- 7/core/jackit-1.9.12-2.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 29 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0476.html
Type: security
CVE: CVE-2019-13351

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here