MGASA-2021-0324 - Updated fluidsynth packages fix a security vulnerability

Publication date: 09 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0324.html
Type: security
Affected Mageia releases: 7, 8
CVE: CVE-2021-21417

fluidsynth is a software synthesizer based on the SoundFont 2 specifications.
A use after free violation was discovered in fluidsynth, that can be triggered
when loading an invalid SoundFont file (CVE-2021-21417).

References:
- https://bugs.mageia.org/show_bug.cgi?id=29051
- https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-6fcq-pxhc-jxc9
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21417

SRPMS:
- 8/core/fluidsynth-2.1.8-1.mga8
- 7/core/fluidsynth-2.0.5-1.1.mga7

Mageia 2021-0324: fluidsynth security update

fluidsynth is a software synthesizer based on the SoundFont 2 specifications

Summary

fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file (CVE-2021-21417).

References

- https://bugs.mageia.org/show_bug.cgi?id=29051

- https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-6fcq-pxhc-jxc9

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21417

Resolution

MGASA-2021-0324 - Updated fluidsynth packages fix a security vulnerability

SRPMS

- 8/core/fluidsynth-2.1.8-1.mga8

- 7/core/fluidsynth-2.0.5-1.1.mga7

Severity
Publication date: 09 Jul 2021
URL: https://advisories.mageia.org/MGASA-2021-0324.html
Type: security
CVE: CVE-2021-21417

Related News