Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

openSUSE 15.4: SUSE-SU-2023:3097-1 Moderate: Pipewire Stream Access Issue

opensuse
Calendar Grey August 1, 2023
Scroller Opensuse
A new patch release for PipeWire resolves the stream access problem affecting openSUSE, categorized as moderate severity.
This update for pipewire fixes the following security issues: Fixed issue where an app which only has permission to access one stream can also access other streams (bsc#1213682).

Description

This update for pipewire fixes the following security issues:

* Fixed issue where an app which only has permission to access one stream can

also access other streams (bsc#1213682).

Bugfixes: \- Fixed division by 0 and other issues with invalid values

(glfo#pipewire/pipewire#2953) \- Fixed an overflow resulting in choppy sound in

some cases (glfo#pipewire/pipewire#2680)

Patch

## Patch Instructions:

To install this SUSE Moderate update use the SUSE recommended installation

methods like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-3097=1

* SUSE Package Hub 15 15-SP4

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-3097=1

* SUSE Package Hub 15 15-SP5

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-3097=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* pipewire-libpulse-0_3-debuginfo-0.3.6-150200.3.9.1

* pipewire-libpulse-0_3-0.3.6-150200.3.9.1

* SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x x86_64)

* pipewire-libpulse-0_3-debuginfo-0.3.6-150200.3.9.1

* pipewire-debugsource-0.3.6-150200.3.9.1

* pipewire-debuginfo-0.3.6-150200.3.9.1

* pipewire-libpulse-0_3-0.3.6-150200.3.9.1

* SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64)

* pipewire-libpulse-0_3-debuginfo-0.3.6-150200.3.9.1

* pipewire-debugsource-0.3.6-150200.3.9.1

* pipewire-debuginfo-0.3.6-150200.3.9.1

* pipewire-libpulse-0_3-0.3.6-150200.3.9.1

References

* #1213682

## References:

* https://bugzilla.suse.com/show_bug.cgi?id=1213682

Announcement ID: SUSE-SU-2023:3097-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.