Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE: 2018:1951-1 Moderate: Libopenmpt Memory Issues Exploited

suse
Calendar Grey July 13, 2018
Scroller Suse
SUSE Patch Resolves Vulnerabilities in Libopenmpt with Moderate Severity. Implement Solutions Immediately.
An update that fixes two vulnerabilities is now available

Summary

This update for libopenmpt to version 0.3.9 fixes the following issues: These security issues were fixed: - CVE-2018-11710: Prevent write near address 0 in out-of-memory situations when reading AMS files (bsc#1095644) - CVE-2018-10017: Preven out-of-bounds memory read with IT/ITP/MO3 files containing pattern loops (bsc#1089080) These non-security issues were fixed: - [Bug] openmpt123: Fixed build failure in C++17 due to use of removed feature std::random_shuffle. - STM: Having both Bxx and Cxx commands in a pattern imported the Bxx command incorrectly. - STM: Last character of sample name was missing. - Speed up reading of truncated ULT files. - ULT: Portamento import was sometimes broken. - The resonant filter was sometimes unstable when combining low-volume samples, low cutoff and high mixing rates.

References

#1089080 #1095644

Cross- CVE-2018-10017 CVE-2018-11710

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2018-10017.html

https://www.suse.com/security/cve/CVE-2018-11710.html

https://bugzilla.suse.com/1089080

https://bugzilla.suse.com/1095644

Announcement ID: SUSE-SU-2018:1951-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.