Update to 4b3d078 (dr_wav 0.13.8): fix a possible null-pointer dereference and a crash when loading files with badly-formed metadata.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-9b87fb6b07 2023-04-22 01:11:17.771528 --------------------------------------------------------------------------------Name : dr_libs Product : Fedora 36 Version : 0^20230324git4b3d078 Release : 0.1.fc36 URL : https://github.com/mackron/dr_libs Summary : Single-file audio decoding libraries for C/C++ Description : Single-file audio decoding libraries for C/C++. --------------------------------------------------------------------------------Update Information: Update to 4b3d078 (dr_wav 0.13.8): fix a possible null-pointer dereference and a crash when loading files with badly-formed metadata. --------------------------------------------------------------------------------ChangeLog: * Wed Apr 12 2023 Benjamin A. Beasley - 0^20230324git4b3d078-0.1 - Update to 4b3d078 (dr_wav 0.13.8) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-9b87fb6b07' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
ClamAV 0.98.7 This release contains new scanning features and bug fixes. - Improvements to PDF processing: decryption, escape sequence handling, and file property collection. - Scanning/analysis of additional Microsoft Office 2003 XML format.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-7346 2015-05-01 11:29:18 -------------------------------------------------------------------------------- Name : clamav Product : Fedora 22 Version : 0.98.7 Release : 1.fc22 URL : http://www.clamav.net Summary : End-user tools for the Clam Antivirus scanner Description : Clam AntiVirus is an anti-virus toolkit for UNIX. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use with your own software. The virus database is based on the virus database from OpenAntiVirus, but contains additional signatures (including signatures for popular polymorphic viruses, too) and is KEPT UP TO DATE. -------------------------------------------------------------------------------- Update Information: ClamAV 0.98.7 ============ This release contains new scanning features and bug fixes. - Improvements to PDF processing: decryption, escape sequence handling, and file property collection. - Scanning/analysis of additional Microsoft Office 2003 XML format. - Fix infinite loop condition on crafted y0da cryptor file. Identified and patch suggested by Sebastian Andrzej Siewior. CVE-2015-2221. - Fix crash on crafted petite packed file. Reported and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2222. - Fix false negatives on files within iso9660 containers. This issue was reported by Minzhuan Gong. - Fix a couple crashes on crafted upackpacked file. Identified and patches supplied by Sebastian Andrzej Siewior. - Fix a crash during algorithmic detection on crafted PE file. Identified and patch supplied by Sebastian Andrzej Siewior. - Fix an infinite loop condition on a crafted "xz" archive file. This was reported by Dimitri Kirchner and Goulven Guiheux. CVE-2015-2668. - Fix compilation error after ./configure --disable-pthreads. Reported and fix suggested by John E. Krokes. - Apply upstream patch for possible heap overflow in Henry Spencer's regex library. CVE-2015-2305. - Fix crash in upx decoder with crafted file. Discovered and patch supplied by Sebastian Andrzej Siewior. CVE-2015-2170. - Fix segfault scanning certain HTML files. Reported with sample by Kai Risku. - Improve detections within xar/pkg files. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1217206 - CVE-2015-2221: clamav Infinite loop condition on crafted y0da cryptor file https://bugzilla.redhat.com/show_bug.cgi?id=1217206 [ 2 ] Bug #1217207 - CVE-2015-2222 clamav: crash on crafted petite packed file https://bugzilla.redhat.com/show_bug.cgi?id=1217207 [ 3 ] Bug #1217208 - CVE-2015-2668 clamav: Infinite loop condition on a crafted "xz" archive file https://bugzilla.redhat.com/show_bug.cgi?id=1217208 [ 4 ] Bug #1217209 - CVE-2015-2170: clamav: Crash in upx decoder with crafted file https://bugzilla.redhat.com/show_bug.cgi?id=1217209 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update clamav' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
File could be made to crash if it processed a specially crafted file.. =========================================================================Ubuntu Security Notice USN-2162-1 April 07, 2014 file vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: File could be made to crash if it processed a specially crafted file. Software Description: - file: Tool to determine file types Details: It was discovered that file incorrectly handled PE executable files. An attacker could use this issue to cause file to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: file 5.11-2ubuntu4.2 libmagic1 5.11-2ubuntu4.2 Ubuntu 12.10: file 5.11-2ubuntu0.2 libmagic1 5.11-2ubuntu0.2 Ubuntu 12.04 LTS: file 5.09-2ubuntu0.3 libmagic1 5.09-2ubuntu0.3 Ubuntu 10.04 LTS: file 5.03-5ubuntu1.2 libmagic1 5.03-5ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2162-1 CVE-2014-2270 Package Information: https://launchpad.net/ubuntu/+source/file/5.11-2ubuntu4.2 https://launchpad.net/ubuntu/+source/file/5.11-2ubuntu0.2 https://launchpad.net/ubuntu/+source/file/5.09-2ubuntu0.3 https://launchpad.net/ubuntu/+source/file/5.03-5ubuntu1.2 . The Ubuntu Security Notice USN-2162-1 highlights a vulnerability related to specific file types that may lead to a denial of service, triggered by specially designed files.. File Types, Ubuntu Security, Denial Of Service, Software Updates. .Severity: Critical. LinuxSecurity.com Team
File could be made to crash if it processed a specially crafted file.. =========================================================================Ubuntu Security Notice USN-2123-1 February 26, 2014 file vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: File could be made to crash if it processed a specially crafted file. Software Description: - file: Tool to determine file types Details: It was discovered that file incorrectly handled Composite Document files. An attacker could use this issue to cause file to crash, resulting in a denial of service. This issue only affected Ubuntu 10.04 LTS and Ubuntu 12.04 LTS. (CVE-2012-1571) Bernd Melchers discovered that file incorrectly handled indirect offset values. An attacker could use this issue to cause file to consume resources or crash, resulting in a denial of service. (CVE-2014-1943) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: file 5.11-2ubuntu4.1 libmagic1 5.11-2ubuntu4.1 Ubuntu 12.10: file 5.11-2ubuntu0.1 libmagic1 5.11-2ubuntu0.1 Ubuntu 12.04 LTS: file 5.09-2ubuntu0.2 libmagic1 5.09-2ubuntu0.2 Ubuntu 10.04 LTS: file 5.03-5ubuntu1.1 libmagic1 5.03-5ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2123-1 CVE-2012-1571, CVE-2014-1943 Package Information: https://launchpad.net/ubuntu/+source/file/5.11-2ubuntu4.1 https://launchpad.net/ubuntu/+source/file/5.11-2ubuntu0.1 https://launchpad.net/ubuntu/+source/file/5.09-2ubuntu0.2 https://launchpad.net/ubuntu/+source/file/5.03-5ubuntu1.1 . Ubuntu Security Alert USN-4123-1 highlights vulnerabilities in package management that could result in system instability or loss of service.. Ubuntu File Security, Denial of Service Risks, Software Crash Issues. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.