Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 7 & 8 - MGASA-2021-0324 Critical Fluidsynth Use After Free

mageia
Calendar Grey July 8, 2021
Dist Mageia Esm H88
MGASA-2021-0325 upgrades gedit to resolve a significant buffer overflow vulnerability impacting Mageia 7 and 8.
fluidsynth is a software synthesizer based on the SoundFont 2 specifications

Summary

fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file (CVE-2021-21417).

References

- https://bugs.mageia.org/show_bug.cgi?id=29051

- https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-6fcq-pxhc-jxc9

- https://www.cve.org/CVERecord?id=CVE-2021-21417

Resolution

SRPMS

- 8/core/fluidsynth-2.1.8-1.mga8

- 7/core/fluidsynth-2.0.5-1.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 09 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0324.html
Type: security
CVE: CVE-2021-21417

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here