Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2025-23457 http://linux.oracle.com/errata/ELSA-2025-23457.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: audiofile-0.3.6-9.0.1.el7.i686.rpm audiofile-0.3.6-9.0.1.el7.x86_64.rpm audiofile-devel-0.3.6-9.0.1.el7.i686.rpm audiofile-devel-0.3.6-9.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/audiofile-0.3.6-9.0.1.el7.src.rpm Related CVEs: CVE-2025-50950 Description of changes: [1:0.3.6-9.0.1] - Fix null pointer dereference [CVE-2025-50950][Orabug: 38777980] [1:0.3.6-9] - Apply security patches. CVE-2018-17095, CVE-2018-13440 - Resolves: rhbz#1600369, rhbz#1601014, rhbz#1637128 [1:0.3.6-8] - Escape macros in %changelog [1:0.3.6-7] - Merge upstream pull requests #42,#43,#44 from Agostino Sarubbo to fix security issues. CVE-2017-6827, CVE-2017-6828, CVE-2017-6829, CVE-2017-6830, CVE-2017-6831, CVE-2017-6832, CVE-2017-6833, CVE-2017-6834, CVE-2017-6835, CVE-2017-6836, CVE-2017-6837, CVE-2017-6838, CVE-2017-6839 [1:0.3.6-6] - patch to compile with GCC 6 [1:0.3.6-5] - Merge fix from upstream pull request #25 for CVE-2015-7747. Test conversion from e.g. 16-bit LE stereo to 8-bit LE mono no longer causes corruption. [1:0.3.6-4] - Mass rebuild 2014-01-24 [1:0.3.6-3] - Mass rebuild 2013-12-27 [0.3.6-1] - audiofile 0.3.6 [0.3.5-1] - audiofile 0.3.5 _______________________________________________ El-errata mailing list
The audiofile library allows the processing of audio data to and from audio files of many common formats (currently AIFF, AIFF-C, WAVE, NeXT/Sun, BICS, and raw data). . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4255-1
* bsc#1140031 * bsc#1196487 Cross-References: * CVE-2019-13147 . # Security update for audiofile Announcement ID: SUSE-SU-2025:02283-1 Release Date: 2025-07-11T08:35:16Z Rating: moderate References: * bsc#1140031 * bsc#1196487 Cross-References: * CVE-2019-13147 * CVE-2022-24599 CVSS scores: * CVE-2019-13147 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2022-24599 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2022-24599 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for audiofile fixes the following issues: * CVE-2019-13147: Do not allow too many channel to prevent NULL pointer dereference (bsc#1140031). * CVE-2022-24599: Clear buffer when allocating (bsc#1196487). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2283=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * audiofile-devel-0.3.6-11.10.1 * libaudiofile1-debuginfo-0.3.6-11.10.1 * libaudiofile1-0.3.6-11.10.1 * audiofile-0.3.6-11.10.1 * audiofile-debugsource-0.3.6-11.10.1 * libaudiofile1-32bit-0.3.6-11.10.1 * libaudiofile1-debuginfo-32bit-0.3.6-11.10.1 * audiofile-debuginfo-0.3.6-11.10.1 ## References: *https://www.suse.com/security/cve/CVE-2019-13147.html * https://www.suse.com/security/cve/CVE-2022-24599.html * https://bugzilla.suse.com/show_bug.cgi?id=1140031 * https://bugzilla.suse.com/show_bug.cgi?id=1196487 . Enhance security on SUSE Enterprise 12 SP5 with essential audiofile updates for identified risks.. SUSE update, audiofile patch, moderate security issue. . LinuxSecurity.com Team
* bsc#1140031 * bsc#1196487 Cross-References: * CVE-2019-13147 . # Security update for audiofile Announcement ID: SUSE-SU-2025:01559-1 Release Date: 2025-06-12T14:50:19Z Rating: moderate References: * bsc#1140031 * bsc#1196487 Cross-References: * CVE-2019-13147 * CVE-2022-24599 CVSS scores: * CVE-2019-13147 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2022-24599 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2022-24599 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for audiofile fixes the following issues: * CVE-2019-13147: Fixed NULL pointer dereference in ulaw2linear_buf that could lead to DOS (bsc#1140031). * CVE-2022-24599: unverified user input when processing audio files can lead to information leak (bsc#1196487). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1559=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * audiofile-devel-0.3.6-150000.3.12.1 * audiofile-debugsource-0.3.6-150000.3.12.1 * libaudiofile1-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-0.3.6-150000.3.12.1 * audiofile-debuginfo-0.3.6-150000.3.12.1 ## References: *https://www.suse.com/security/cve/CVE-2019-13147.html * https://www.suse.com/security/cve/CVE-2022-24599.html * https://bugzilla.suse.com/show_bug.cgi?id=1140031 * https://bugzilla.suse.com/show_bug.cgi?id=1196487 . SUSE patch 2025:01559-1 addresses critical vulnerabilities in audiofile, boosting stability and security for audio processing; admins must apply this update swiftly. SUSE, audiofile, security advisory, patch, DoS. . LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for audiofile Announcement ID: SUSE-SU-2025:1559-1 Release Date: 2025-05-15T11:19:29Z Rating: moderate References: * bsc#1140031 * bsc#1196487 Cross-References: * CVE-2019-13147 * CVE-2022-24599 CVSS scores: * CVE-2019-13147 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2022-24599 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2022-24599 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for audiofile fixes the following issues: * CVE-2019-13147: Fixed NULL pointer dereference in ulaw2linear_buf that could lead to DOS (bsc#1140031). * CVE-2022-24599: unverified user input when processing audio files can lead to information leak (bsc#1196487). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1559=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1559=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * audiofile-0.3.6-150000.3.12.1 * audiofile-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-0.3.6-150000.3.12.1 *audiofile-debugsource-0.3.6-150000.3.12.1 * audiofile-devel-0.3.6-150000.3.12.1 * audiofile-doc-0.3.6-150000.3.12.1 * openSUSE Leap 15.6 (x86_64) * libaudiofile1-32bit-debuginfo-0.3.6-150000.3.12.1 * audiofile-devel-32bit-0.3.6-150000.3.12.1 * libaudiofile1-32bit-0.3.6-150000.3.12.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * audiofile-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-0.3.6-150000.3.12.1 * audiofile-debugsource-0.3.6-150000.3.12.1 * audiofile-devel-0.3.6-150000.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2019-13147.html * https://www.suse.com/security/cve/CVE-2022-24599.html * https://bugzilla.suse.com/show_bug.cgi?id=1140031 * https://bugzilla.suse.com/show_bug.cgi?id=1196487 . A patch for the software package resolves three security flaws in Fedora, which could allow unauthorized access and create possibilities for data breaches.. openSUSE, audiofile, security update, DoS, information leak. . LinuxSecurity.com Team
* bsc#1140031 * bsc#1196487 Cross-References: * CVE-2019-13147 . # Security update for audiofile Announcement ID: SUSE-SU-2025:1559-1 Release Date: 2025-05-15T11:19:29Z Rating: moderate References: * bsc#1140031 * bsc#1196487 Cross-References: * CVE-2019-13147 * CVE-2022-24599 CVSS scores: * CVE-2019-13147 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2019-13147 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2022-24599 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2022-24599 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * Desktop Applications Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for audiofile fixes the following issues: * CVE-2019-13147: Fixed NULL pointer dereference in ulaw2linear_buf that could lead to DOS (bsc#1140031). * CVE-2022-24599: unverified user input when processing audio files can lead to information leak (bsc#1196487). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1559=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2025-1559=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * audiofile-0.3.6-150000.3.12.1 * audiofile-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-0.3.6-150000.3.12.1 *audiofile-debugsource-0.3.6-150000.3.12.1 * audiofile-devel-0.3.6-150000.3.12.1 * audiofile-doc-0.3.6-150000.3.12.1 * openSUSE Leap 15.6 (x86_64) * libaudiofile1-32bit-debuginfo-0.3.6-150000.3.12.1 * audiofile-devel-32bit-0.3.6-150000.3.12.1 * libaudiofile1-32bit-0.3.6-150000.3.12.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * audiofile-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-debuginfo-0.3.6-150000.3.12.1 * libaudiofile1-0.3.6-150000.3.12.1 * audiofile-debugsource-0.3.6-150000.3.12.1 * audiofile-devel-0.3.6-150000.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2019-13147.html * https://www.suse.com/security/cve/CVE-2022-24599.html * https://bugzilla.suse.com/show_bug.cgi?id=1140031 * https://bugzilla.suse.com/show_bug.cgi?id=1196487 . SUSE unveils crucial security patch for audiofile addressing significant vulnerabilities tied to data exposure and denial-of-service risks.. SUSE Security Update, audiofile vulnerabilities, moderate severity threats. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # audiofile-0.3.6-15.1 on GA media Announcement ID: openSUSE-SU-2025:15050-1 Rating: moderate Cross-References: * CVE-2022-24599 CVSS scores: * CVE-2022-24599 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the audiofile-0.3.6-15.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * audiofile 0.3.6-15.1 * audiofile-devel 0.3.6-15.1 * audiofile-doc 0.3.6-15.1 * libaudiofile1 0.3.6-15.1 ## References: * https://www.suse.com/security/cve/CVE-2022-24599.html . A recent enhancement for openSUSE Tumbleweed tackles a significant vulnerability in audiofile-0.3.6-15.1. See CVE-2022-24599 for further details.. openSUSE update, audiofile package, moderate security issue, CVE-2022-24599. . LinuxSecurity.com Team
2 patches are added to audiofile source to correct a vulnerability. In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file. (CVE-2019-13147) . MGASA-2023-0347 - Updated audiofile packages fix a security vulnerability Publication date: 15 Dec 2023 URL: https://advisories.mageia.org/MGASA-2023-0347.html Type: security Affected Mageia releases: 9 CVE: CVE-2019-13147 2 patches are added to audiofile source to correct a vulnerability. In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file. (CVE-2019-13147) References: - https://bugs.mageia.org/show_bug.cgi?id=32608 - https://www.cve.org/CVERecord?id=CVE-2019-13147 SRPMS: - 9/core/audiofile-0.3.6-14.mga9 . Revised multimedia bundles resolve a significant vulnerability in Mageia editions, affecting the security of audio handling.. Audio Security Update,Mageia 2023,Denial of Service Fix,Audiofile Vulnerability,Security Patch Mageia. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.