Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

SUSE: 2018:3606-1 Moderate: Soundtouch DoS Threat Update

suse
Calendar Grey November 2, 2018
Dist Suse Esm H88
SUSE Security Patch resolves soundtouch vulnerabilities, enhancing both efficiency and protection for your platform.
An update that fixes three vulnerabilities is now available

Summary

This update for soundtouch fixes the following issues: - CVE-2018-17098: The WavFileBase class allowed remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. (bsc#1108632) - CVE-2018-17097: The WavFileBase class allowed remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch. (double free) (bsc#1108631) - CVE-2018-17096: The BPMDetect class allowed remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch. (bsc#1108630) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1108630 #1108631 #1108632

Cross- CVE-2018-17096 CVE-2018-17097 CVE-2018-17098

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP3

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2018-17096.html

https://www.suse.com/security/cve/CVE-2018-17097.html

https://www.suse.com/security/cve/CVE-2018-17098.html

https://bugzilla.suse.com/1108630

https://bugzilla.suse.com/1108631

https://bugzilla.suse.com/1108632

Announcement ID: SUSE-SU-2018:3606-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here