Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Ubuntu 4033-1: Crash Vulnerability Found in libmysofa Library

Ubuntu Large Esm H500
libmysofa could be made to crash if it received specially crafted input.
=========================================================================Ubuntu Security Notice USN-4033-1
June 24, 2019

libmysofa vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS

Summary:

libmysofa could be made to crash if it received specially crafted
input.

Software Description:
- libmysofa: library to read HRTFs stored in the AES69-2015 SOFA format

Details:

It was discovered that a libmysofa component does not properly validate
multiplications and additions, and may crash with some specific input.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
  libmysofa0                      0.6~dfsg0-2ubuntu0.19.04.1

Ubuntu 18.10:
  libmysofa0                      0.6~dfsg0-2ubuntu0.18.10.1

Ubuntu 18.04 LTS:
  libmysofa0                      0.6~dfsg0-2ubuntu0.18.04.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4033-1
  CVE-2019-10672

Package Information:
  https://launchpad.net/ubuntu/+source/libmysofa/0.6~dfsg0-2ubuntu0.19.04.1
  https://launchpad.net/ubuntu/+source/libmysofa/0.6~dfsg0-2ubuntu0.18.10.1
  https://launchpad.net/ubuntu/+source/libmysofa/0.6~dfsg0-2ubuntu0.18.04.1

Ubuntu 4033-1: Crash Vulnerability Found in libmysofa Library

ubuntu
Calendar Grey June 24, 2019
Dist Ubuntu Esm H88
The libmysofa flaw poses a risk of system disruptions due to maliciously designed input on Ubuntu platforms. Users are advised to apply updates for the impacted versions.
libmysofa could be made to crash if it received specially crafted input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: libmysofa0 0.6~dfsg0-2ubuntu0.19.04.1 Ubuntu 18.10: libmysofa0 0.6~dfsg0-2ubuntu0.18.10.1 Ubuntu 18.04 LTS: libmysofa0 0.6~dfsg0-2ubuntu0.18.04.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4033-1

CVE-2019-10672

Severity
critical
Lowest
Low
Medium
High
Critical

June 24, 2019

Package Information

https://launchpad.net/ubuntu/+source/libmysofa/0.6~dfsg0-2ubuntu0.19.04.1 https://launchpad.net/ubuntu/+source/libmysofa/0.6~dfsg0-2ubuntu0.18.10.1 https://launchpad.net/ubuntu/+source/libmysofa/0.6~dfsg0-2ubuntu0.18.04.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here