Latest Monkey's Audio Codec release. Changelog: https://monkeysaudio.com/versionhistory.html . Fixes CVE-2025-61043.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-62f9125c65 2026-03-19 00:15:36.606391+00:00 -------------------------------------------------------------------------------- Name : mac Product : Fedora 44 Version : 12.50 Release : 1.fc44 URL : https://monkeysaudio.com Summary : Monkey's Audio Codec Description : Monkey's Audio is a fast and easy way to compress digital music. Unlike traditional methods such as mp3, ogg, or lqt that permanently discard quality to save space, Monkey's Audio only makes perfect, bit-for-bit copies of your music. That means it always sounds perfect \u2013 exactly the same as the original. Even though the sound is perfect, it still saves a lot of space. -------------------------------------------------------------------------------- Update Information: Latest Monkey's Audio Codec release. Changelog: https://monkeysaudio.com/versionhistory.html . Fixes CVE-2025-61043. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 10 2026 Dominik 'Rathann' Mierzejewski - 12.50-1 - Updated to 12.50 (resolves rhbz#2363650) * Tue Feb 24 2026 Dominik 'Rathann' Mierzejewski - 12.35-3 - assume platform is Linux in headers if unspecified * Mon Feb 23 2026 Dominik 'Rathann' Mierzejewski - 12.35-2 - bump minimum CMake version (resolves rhbz#2380887) * Mon Feb 23 2026 Dominik 'Rathann' Mierzejewski - 12.35-1 - update to 12.35 (resolves rhbz#2363650) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2363650 - mac-12.50 is available https://bugzilla.redhat.com/show_bug.cgi?id=2363650 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-62f9125c65' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Discover the latest update on Monkey's Audio Codec addressing CVE-2025-61043 with critical fixes and enhancements.. Fedora 44, Monkey's Audio, security update, important patch, CVE 2025. . Severity: Important. LinuxSecurity.com Team
Fix for CVE-2021-44269. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-737f020ede 2022-04-21 20:57:05.212004 --------------------------------------------------------------------------------Name : wavpack Product : Fedora 34 Version : 5.4.0 Release : 5.fc34 URL : https://www.wavpack.com/ Summary : A completely open audiocodec Description : WavPack is a completely open audio compression format providing lossless, high-quality lossy, and a unique hybrid compression mode. Although the technology is loosely based on previous versions of WavPack, the new version 4 format has been designed from the ground up to offer unparalleled performance and functionality. --------------------------------------------------------------------------------Update Information: Fix for CVE-2021-44269 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 6 2022 Peter Lemenkov - 5.4.0-5 - Fix for CVE-2021-44269 * Sat Jan 22 2022 Fedora Release Engineering - 5.4.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Fri Jul 23 2021 Fedora Release Engineering - 5.4.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2067997 - CVE-2021-44269 wavpack: heap Out-of-bounds Read [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2067997 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-737f020ede' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-0561. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-ee96acc54f 2022-03-26 14:56:28.650365 --------------------------------------------------------------------------------Name : flac Product : Fedora 36 Version : 1.3.4 Release : 1.fc36 URL : https://www.xiph.org/flac/ Summary : An encoder/decoder for the Free Lossless Audio Codec Description : FLAC stands for Free Lossless Audio Codec. Grossly oversimplified, FLAC is similar to Ogg Vorbis, but lossless. The FLAC project consists of the stream format, reference encoders and decoders in library form, flac, a command-line program to encode and decode FLAC files, metaflac, a command-line metadata editor for FLAC files and input plugins for various music players. This package contains the command-line tools and documentation. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-0561 --------------------------------------------------------------------------------ChangeLog: * Thu Feb 24 2022 Miroslav Lichvar 1.3.4-1 - update to 1.3.4 (CVE-2021-0561) --------------------------------------------------------------------------------References: [ 1 ] Bug #2057776 - CVE-2021-0561 flac: out of bound write in append_to_verify_fifo_interleaved_ of stream_encoder.c https://bugzilla.redhat.com/show_bug.cgi?id=2057776 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-ee96acc54f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several vulnerabilities were fixed in libvorbis, a popular library for the Vorbis audio codec. CVE-2017-14160 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2828-1
WavPack could be made to execute arbitrary code or crash if it received a specially crafted WAV file.. =========================================================================Ubuntu Security Notice USN-4682-1 January 06, 2021 wavpack vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: WavPack could be made to execute arbitrary code or crash if it received a specially crafted WAV file. Software Description: - wavpack: audio codec (lossy and lossless) - encoder and decoder Details: It was discovered that WavPack incorrectly handled certain WAV files. An attacker could possibly use this issue to execute arbitrary code or cause a crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: wavpack 5.3.0-1ubuntu0.1 Ubuntu 20.04 LTS: wavpack 5.2.0-1ubuntu0.1 Ubuntu 18.04 LTS: wavpack 5.1.0-2ubuntu1.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4682-1 CVE-2020-35738 Package Information: https://launchpad.net/ubuntu/+source/wavpack/5.3.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/wavpack/5.2.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu1.5 . The WavPack security flaw might enable code execution or cause system failures through specially designed WAV files on Ubuntu platforms.. WavPack Security, Ubuntu Updates, Code Execution Threat. . Severity: Critical. LinuxSecurity.com Team
Two issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. . Package : libvorbis Version : 1.3.4-2+deb8u3 CVE ID : CVE-2017-11333 CVE-2017-14633 Two issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. 2017-14633 In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis(). 2017-11333 The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file. For Debian 8 "Jessie", these problems have been fixed in version 1.3.4-2+deb8u3. We recommend that you upgrade your libvorbis packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Significant vulnerabilities in libvorbis addressed in Debian 8 Jessie. Users should update to avoid potential service interruptions.. libvorbis security update, Debian 8 Jessie, audio library issues, critical security patch. . Severity: Critical. LinuxSecurity.com Team
Several issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. . Package : libvorbis Version : 1.3.4-2+deb8u2 CVE ID : CVE-2017-14160 CVE-2018-10392 CVE-2018-10393 Several issues have been found in libvorbis, a decoder library for Vorbis General Audio Compression Codec. The fix for CVE-2017-14160 and CVE-2018-10393 improve the bound checking for very low sample rates. CVE-2018-10392 was found because the number of channels was not validated and a remote attacker could cause a denial of service. For Debian 8 "Jessie", these problems have been fixed in version 1.3.4-2+deb8u2. We recommend that you upgrade your libvorbis packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest update for libvorbis resolves various vulnerabilities, enhancing security protocols and eliminating denial of service risks.. libvorbis security update, Debian LTS advisory, audio codec vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Fix for CVE-2019-1010317 and CVE-2019-1010319. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-c72f5f6361 2019-09-03 12:32:24.093439 --------------------------------------------------------------------------------Name : wavpack Product : Fedora 30 Version : 5.1.0 Release : 16.fc30 URL : https://www.wavpack.com/ Summary : A completely open audiocodec Description : WavPack is a completely open audio compression format providing lossless, high-quality lossy, and a unique hybrid compression mode. Although the technology is loosely based on previous versions of WavPack, the new version 4 format has been designed from the ground up to offer unparalleled performance and functionality. --------------------------------------------------------------------------------Update Information: Fix for CVE-2019-1010317 and CVE-2019-1010319 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 19 2019 Tomas Korbar - 5.1.0-16 - Fix for CVE-2019-1010317 * Mon Aug 19 2019 Tomas Korbar - 5.1.0-15 - Fix for CVE-2019-1010319 * Sat Jul 27 2019 Fedora Release Engineering - 5.1.0-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Fri May 17 2019 Peter Lemenkov - 5.1.0-13 - Fix for CVE-2019-11498 --------------------------------------------------------------------------------References: [ 1 ] Bug #1737740 - CVE-2019-1010319 wavpack: use of uninitialized variable in ParseWave64HeaderConfig leads to DoS https://bugzilla.redhat.com/show_bug.cgi?id=1737740 [ 2 ] Bug #1737747 - CVE-2019-1010317 wavpack: use of uninitialized variable in ParseCaffHeaderConfig leads to DoS https://bugzilla.redhat.com/show_bug.cgi?id=1737747 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2019-c72f5f6361' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.