Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2018:3610-1 Moderate: soundtouch Denial Of Service Issues

suse
Calendar Grey November 2, 2018
Dist Suse Esm H88
SUSE releases urgent soundtouch fix addressing a trio of vulnerabilities. Implement updates to boost security and performance.
An update that fixes three vulnerabilities is now available

Summary

This update for soundtouch fixes the following issues: - CVE-2018-17098: The WavFileBase class allowed remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. (bsc#1108632) - CVE-2018-17097: The WavFileBase class allowed remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch. (double free) (bsc#1108631) - CVE-2018-17096: The BPMDetect class allowed remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch. (bsc#1108630) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1108630 #1108631 #1108632

Cross- CVE-2018-17096 CVE-2018-17097 CVE-2018-17098

Affected Products:

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15

SUSE Linux Enterprise Module for Desktop Applications 15

https://www.suse.com/security/cve/CVE-2018-17096.html

https://www.suse.com/security/cve/CVE-2018-17097.html

https://www.suse.com/security/cve/CVE-2018-17098.html

https://bugzilla.suse.com/1108630

https://bugzilla.suse.com/1108631

https://bugzilla.suse.com/1108632

Announcement ID: SUSE-SU-2018:3610-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here