Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for libsndfile fixes the following issues:
* CVE-2022-33065: Fixed an integer overflow that could cause memory safety
issues when reading a MAT4 file (bsc#1213451).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4330=1
* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2
zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4330=1
* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3
zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4330=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP1
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4330=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP2
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4330=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP3
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4330=1
* SUSE Manager Proxy 4.2
zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4330=1
*...
Read the Full Advisory* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x
x86_64)
* libsndfile1-1.0.28-150000.5.20.1
* libsndfile-debugsource-1.0.28-150000.5.20.1
* libsndfile1-debuginfo-1.0.28-150000.5.20.1
* libsndfile-devel-1.0.28-150000.5.20.1
* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (x86_64)
* libsndfile1-32bit-1.0.28-150000.5.20.1
* libsndfile1-32bit-debuginfo-1.0.28-150000.5.20.1
* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x
x86_64)
* libsndfile1-1.0.28-150000.5.20.1
* libsndfile-debugsource-1.0.28-150000.5.20.1
* libsndfile1-debuginfo-1.0.28-150000.5.20.1
* libsndfile-devel-1.0.28-150000.5.20.1
* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x
x86_64)
* libsndfile1-1.0.28-150000.5.20.1
* libsndfile-debugsource-1.0.28-150000.5.20.1
* libsndfile1-debuginfo-1.0.28-150000.5.20.1
* libsndfile-devel-1.0.28-150000.5.20.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64)
* libsndfile1-1.0.28-150000.5.20.1
*...
Read the Full Advisory* bsc#1213451
## References:
* https://www.suse.com/security/cve/CVE-2022-33065.html
* https://bugzilla.suse.com/show_bug.cgi?id=1213451
Get the latest Linux and open source security news straight to your inbox.