Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for aubio ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1852-1 Rating: moderate References: #1137823 #1142433 #1142435 #1142436 Cross-References: CVE-2018-19802 CVE-2019-1010222 CVE-2019-1010223 CVE-2019-1010224 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for aubio fixes the following issues: - CVE-2019-1010224: Fixed a denial of service (boo#1142435). This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1852=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): python-aubio-debugsource-0.4.6-bp150.3.15.1 python2-aubio-0.4.6-bp150.3.15.1 python2-aubio-debuginfo-0.4.6-bp150.3.15.1 python3-aubio-0.4.6-bp150.3.15.1 python3-aubio-debuginfo-0.4.6-bp150.3.15.1 - openSUSE Backports SLE-15 (x86_64): aubio-tools-0.4.6-bp150.3.15.1 libaubio-devel-0.4.6-bp150.3.15.1 libaubio5-0.4.6-bp150.3.15.1 References: https://www.suse.com/security/cve/CVE-2018-19802.html https://www.suse.com/security/cve/CVE-2019-1010222.html https://www.suse.com/security/cve/CVE-2019-1010223.html https://www.suse.com/security/cve/CVE-2019-1010224.html https://bugzilla.suse.com/1137823 https://bugzilla.suse.com/1142433 https://bugzilla.suse.com/1142435 https://bugzilla.suse.com/1142436 -- . A new version ofopenSUSE aubio has been released to remedy moderate severity vulnerabilities related to service disruption. The fix is now accessible.. openSUSE, aubio, security updates, software vulnerabilities. . LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for aubio ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1834-1 Rating: moderate References: #1137823 #1142433 #1142435 #1142436 Cross-References: CVE-2018-19802 CVE-2019-1010222 CVE-2019-1010223 CVE-2019-1010224 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for aubio fixes the following issues: - CVE-2019-1010224: Fixed a denial of service (boo#1142435). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1834=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): aubio-debugsource-0.4.6-lp150.3.13.1 aubio-tools-0.4.6-lp150.3.13.1 aubio-tools-debuginfo-0.4.6-lp150.3.13.1 libaubio-devel-0.4.6-lp150.3.13.1 libaubio5-0.4.6-lp150.3.13.1 libaubio5-debuginfo-0.4.6-lp150.3.13.1 - openSUSE Leap 15.0 (x86_64): libaubio5-32bit-0.4.6-lp150.3.13.1 libaubio5-32bit-debuginfo-0.4.6-lp150.3.13.1 python-aubio-debugsource-0.4.6-lp150.3.13.1 python2-aubio-0.4.6-lp150.3.13.1 python2-aubio-debuginfo-0.4.6-lp150.3.13.1 python3-aubio-0.4.6-lp150.3.13.1 python3-aubio-debuginfo-0.4.6-lp150.3.13.1 References: https://www.suse.com/security/cve/CVE-2018-19802.html https://www.suse.com/security/cve/CVE-2019-1010222.html https://www.suse.com/security/cve/CVE-2019-1010223.html https://www.suse.com/security/cve/CVE-2019-1010224.html https://bugzilla.suse.com/1137823 https://bugzilla.suse.com/1142433 https://bugzilla.suse.com/1142435 https://bugzilla.suse.com/1142436 -- . New release for openSUSE users has been announced, tackling aubio security flaws and correcting several vulnerabilities.. openSUSE Update, Aubio Security, Patch Instructions, Moderate Severity, Denial of Service. . LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for aubio ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1624-1 Rating: moderate References: #1137822 #1137823 #1137828 Cross-References: CVE-2018-19800 CVE-2018-19801 CVE-2018-19802 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for aubio fixes the following issues: Fixed security issues leading to buffer overflows or segfaults (CVE-2018-19800, boo#1137828, CVE-2018-19801, boo#1137822, CVE-2018-19802, boo#1137823): This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1624=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): python-aubio-debugsource-0.4.6-bp150.3.12.1 python2-aubio-0.4.6-bp150.3.12.1 python2-aubio-debuginfo-0.4.6-bp150.3.12.1 python3-aubio-0.4.6-bp150.3.12.1 python3-aubio-debuginfo-0.4.6-bp150.3.12.1 - openSUSE Backports SLE-15 (x86_64): aubio-tools-0.4.6-bp150.3.12.1 libaubio-devel-0.4.6-bp150.3.12.1 libaubio5-0.4.6-bp150.3.12.1 References: https://www.suse.com/security/cve/CVE-2018-19800.html https://www.suse.com/security/cve/CVE-2018-19801.html https://www.suse.com/security/cve/CVE-2018-19802.html https://bugzilla.suse.com/1137822 https://bugzilla.suse.com/1137823 https://bugzilla.suse.com/1137828 -- . openSUSE Security Update: Security update foraubio ________________________________________________. update, security, fixes, three, vulnerabilities, opensuse. . LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for aubio ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1618-1 Rating: moderate References: #1137822 #1137823 #1137828 Cross-References: CVE-2018-19800 CVE-2018-19801 CVE-2018-19802 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for aubio fixes the following issues: Fixed security issues leading to buffer overflows or segfaults (CVE-2018-19800, boo#1137828, CVE-2018-19801, boo#1137822, CVE-2018-19802, boo#1137823): Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1618=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1618=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1618=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): aubio-debugsource-0.4.1-9.13.1 aubio-tools-0.4.1-9.13.1 aubio-tools-debuginfo-0.4.1-9.13.1 libaubio-devel-0.4.1-9.13.1 libaubio4-0.4.1-9.13.1 libaubio4-debuginfo-0.4.1-9.13.1 - openSUSE Leap 42.3 (x86_64): libaubio4-32bit-0.4.1-9.13.1 libaubio4-debuginfo-32bit-0.4.1-9.13.1 - openSUSE Leap 15.1 (i586 x86_64): aubio-debugsource-0.4.6-lp151.6.3.1 aubio-tools-0.4.6-lp151.6.3.1 aubio-tools-debuginfo-0.4.6-lp151.6.3.1 libaubio-devel-0.4.6-lp151.6.3.1 libaubio5-0.4.6-lp151.6.3.1 libaubio5-debuginfo-0.4.6-lp151.6.3.1 - openSUSE Leap15.1 (x86_64): libaubio5-32bit-0.4.6-lp151.6.3.1 libaubio5-32bit-debuginfo-0.4.6-lp151.6.3.1 python-aubio-debugsource-0.4.6-lp151.6.3.1 python2-aubio-0.4.6-lp151.6.3.1 python2-aubio-debuginfo-0.4.6-lp151.6.3.1 python3-aubio-0.4.6-lp151.6.3.1 python3-aubio-debuginfo-0.4.6-lp151.6.3.1 - openSUSE Leap 15.0 (i586 x86_64): aubio-debugsource-0.4.6-lp150.3.10.1 aubio-tools-0.4.6-lp150.3.10.1 aubio-tools-debuginfo-0.4.6-lp150.3.10.1 libaubio-devel-0.4.6-lp150.3.10.1 libaubio5-0.4.6-lp150.3.10.1 libaubio5-debuginfo-0.4.6-lp150.3.10.1 - openSUSE Leap 15.0 (x86_64): libaubio5-32bit-0.4.6-lp150.3.10.1 libaubio5-32bit-debuginfo-0.4.6-lp150.3.10.1 python-aubio-debugsource-0.4.6-lp150.3.10.1 python2-aubio-0.4.6-lp150.3.10.1 python2-aubio-debuginfo-0.4.6-lp150.3.10.1 python3-aubio-0.4.6-lp150.3.10.1 python3-aubio-debuginfo-0.4.6-lp150.3.10.1 References: https://www.suse.com/security/cve/CVE-2018-19800.html https://www.suse.com/security/cve/CVE-2018-19801.html https://www.suse.com/security/cve/CVE-2018-19802.html https://bugzilla.suse.com/1137822 https://bugzilla.suse.com/1137823 https://bugzilla.suse.com/1137828 -- . A recent openSUSE Security Patch addresses vulnerabilities related to memory overflows in aubio, boosting system reliability.. openSUSE Security Update,aubio patch,buffer overflow fix. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for aubio ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1229-1 Rating: moderate References: #1102359 #1102364 Cross-References: CVE-2018-14522 CVE-2018-14523 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for aubio fixes the following issues: - CVE-2018-14522: Fixed a crash in aubio_pitch_set_unit (bsc#1102359) - CVE-2018-14523: Fixed a buffer overrread resulting in crash or information leakage in new_aubio_pitchyinfft (bsc#1102364) This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1229=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): python-aubio-debugsource-0.4.6-bp150.3.9.1 python2-aubio-0.4.6-bp150.3.9.1 python2-aubio-debuginfo-0.4.6-bp150.3.9.1 python3-aubio-0.4.6-bp150.3.9.1 python3-aubio-debuginfo-0.4.6-bp150.3.9.1 - openSUSE Backports SLE-15 (x86_64): aubio-tools-0.4.6-bp150.3.9.1 libaubio-devel-0.4.6-bp150.3.9.1 libaubio5-0.4.6-bp150.3.9.1 References: https://www.suse.com/security/cve/CVE-2018-14522.html https://www.suse.com/security/cve/CVE-2018-14523.html https://bugzilla.suse.com/1102359 https://bugzilla.suse.com/1102364 -- . Notice for openSUSE: A security patch for aubio resolves moderate vulnerabilities related to system crashes and potential data exposure.. aubio securityupdate, openSUSE patches, moderate security issue. . LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for aubio ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1049-1 Rating: moderate References: #1102359 #1102364 Cross-References: CVE-2018-14522 CVE-2018-14523 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for aubio fixes the following issues: - CVE-2018-14522: Fixed a crash in aubio_pitch_set_unit (bsc#1102359) - CVE-2018-14523: Fixed a buffer overrread resulting in crash or information leakage in new_aubio_pitchyinfft (bsc#1102364) This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2019-1049=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): aubio-debugsource-0.4.1-bp150.3.6.1 aubio-tools-0.4.1-bp150.3.6.1 aubio-tools-debuginfo-0.4.1-bp150.3.6.1 libaubio-devel-0.4.1-bp150.3.6.1 libaubio4-0.4.1-bp150.3.6.1 libaubio4-debuginfo-0.4.1-bp150.3.6.1 - openSUSE Backports SLE-15 (aarch64_ilp32): libaubio4-64bit-0.4.1-bp150.3.6.1 libaubio4-64bit-debuginfo-0.4.1-bp150.3.6.1 References: https://www.suse.com/security/cve/CVE-2018-14522.html https://www.suse.com/security/cve/CVE-2018-14523.html https://bugzilla.suse.com/1102359 https://bugzilla.suse.com/1102364 -- . This revision resolves several concerns within aubio for openSUSE Backports SLE-15, improving overall system reliability and safeguardingsecurity.. openSUSE Auburn Update, Moderate Security Advisory, Package Management. . LinuxSecurity.com Team
The package aubio before version 0.4.9-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201902-8 ======================================== Severity: Medium Date : 2019-02-12 CVE-ID : CVE-2018-19800 CVE-2018-19801 CVE-2018-19802 Package : aubio Type : denial of service Remote : No Link : https://security.archlinux.org/AVG-888 Summary ====== The package aubio before version 0.4.9-1 is vulnerable to denial of service. Resolution ========= Upgrade to 0.4.9-1. # pacman -Syu "aubio> =0.4.9-1" The problems have been fixed upstream in version 0.4.9. Workaround ========= None. Description ========== - CVE-2018-19800 (denial of service) A potential buffer overflow vulnerability was found on invalid new_aubio-tempo in aubio before 0.4.9, which may lead to application crash when playing a crafted audio file. - CVE-2018-19801 (denial of service) A NULL pointer dereference (denial of service) vulnerability was found on invalid n_filters in aubio before 0.4.9, which may lead to application crash when playing a crafted audio file. - CVE-2018-19802 (denial of service) A NULL pointer dereference (denial of service) vulnerability was found on invalid new_aubio_onset in aubio before 0.4.9, which may lead to application crash when playing a crafted audio file. Impact ===== An attacker might be able to crash the software by tricking the user into opening a crafted audio file. References ========= https://github.com/aubio/aubio/blob/0.4.9/ChangeLog#L14-L17 https://github.com/aubio/aubio/commit/1cf031a3a5b869368562b1251419fd45191eaa53 https://github.com/aubio/aubio/commit/bcc53876548334b4c5f1ebd47a5bd5f151974e8b https://github.com/aubio/aubio/commit/c5ee1307bdc004e43302abeca1802c2692b33a8e https://security.archlinux.org/CVE-2018-19800 https://security.archlinux.org/CVE-2018-19801 https://security.archlinux.org/CVE-2018-19802 . Arch Linux Notification regarding aubio package concerning potential denial of servicevulnerabilities effective February 12, 2019 rated at medium severity.. aubio denial service, arch linux advisory, medium severity vulnerabilities, package security issue. . Severity: Medium. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for aubio ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2810-1 Rating: moderate References: #1102359 #1102364 Cross-References: CVE-2018-14522 CVE-2018-14523 Affected Products: openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for aubio fixes the following issues: - CVE-2018-14522: Fixed a crash in aubio_pitch_set_unit (bsc#1102359) - CVE-2018-14523: Fixed a buffer overrread resulting in crash or information leakage in new_aubio_pitchyinfft (bsc#1102364) This update was imported from the openSUSE:Leap:15.0:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2018-883=1 Package List: - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): python-aubio-debugsource-0.4.6-bp150.3.3.1 python2-aubio-0.4.6-bp150.3.3.1 python2-aubio-debuginfo-0.4.6-bp150.3.3.1 python3-aubio-0.4.6-bp150.3.3.1 python3-aubio-debuginfo-0.4.6-bp150.3.3.1 - openSUSE Backports SLE-15 (x86_64): aubio-tools-0.4.6-bp150.3.3.1 libaubio-devel-0.4.6-bp150.3.3.1 libaubio5-0.4.6-bp150.3.3.1 References: https://www.suse.com/security/cve/CVE-2018-14522.html https://www.suse.com/security/cve/CVE-2018-14523.html https://bugzilla.suse.com/1102359 https://bugzilla.suse.com/1102364 -- . A recent announcement from openSUSE highlights the resolution of two security flaws in aubio, bolstering both software reliability and its protectionmechanisms.. openSUSE Security Update,aubio fixes,software threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.