Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

openSUSE Leap 42.3 & 15.0: 2018:1686-1 Low: Taglib Information Disclosure

opensuse
Calendar Grey June 13, 2018
Dist Opensuse Esm H88
A patch for taglib has been released in openSUSE, resolving a minor security issue that could lead to information leakage via a specially crafted audio file.
An update that fixes one vulnerability is now available.

Description

This update for taglib fixes this security issues:

- CVE-2018-11439: The TagLib::Ogg::FLAC::File::scan function allowed

remote attackers to cause information disclosure (heap-based buffer

over-read) via a crafted audio file (bsc#1096180).

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-627=1

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-627=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

libtag-devel-1.11-8.1

libtag1-1.11-8.1

libtag1-debuginfo-1.11-8.1

libtag_c0-1.11-8.1

libtag_c0-debuginfo-1.11-8.1

taglib-1.11-8.1

taglib-debuginfo-1.11-8.1

taglib-debugsource-1.11-8.1

- openSUSE Leap 42.3 (x86_64):

libtag1-32bit-1.11-8.1

libtag1-debuginfo-32bit-1.11-8.1

libtag_c0-32bit-1.11-8.1

libtag_c0-debuginfo-32bit-1.11-8.1

- openSUSE Leap 15.0 (i586 x86_64):

libtag-devel-1.11.1-lp150.3.3.1

libtag1-1.11.1-lp150.3.3.1

libtag1-debuginfo-1.11.1-lp150.3.3.1

libtag_c0-1.11.1-lp150.3.3.1

libtag_c0-debuginfo-1.11.1-lp150.3.3.1

taglib-1.11.1-lp150.3.3.1

taglib-debuginfo-1.11.1-lp150.3.3.1

taglib-debugsource-1.11.1-lp150.3.3.1

- openSUSE Leap 15.0 (x86_64):

libtag1-32bit-1.11.1-lp150.3.3.1

libtag1-32bit-debuginfo-1.11.1-lp150.3.3.1

libtag_c0-32bit-1.11.1-lp150.3.3.1

libtag_c0-32bit-debuginfo-1.11.1-lp150.3.3.1

References

https://www.suse.com/security/cve/CVE-2018-11439.html

https://bugzilla.suse.com/1096180

--

Severity
low
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:1686-1
Rating: low
Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here