A flaw was found in libao. The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 can cause a denial of service(memory corruption) via a crafted mp3 file (CVE-2017-11548). References: . MGASA-2019-0018 - Updated libao packages fix security vulnerability Publication date: 06 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0018.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-11548 A flaw was found in libao. The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 can cause a denial of service(memory corruption) via a crafted mp3 file (CVE-2017-11548). References: - https://bugs.mageia.org/show_bug.cgi?id=23402 - https://lists.fedoraproject.org/archives/list/
Backport fix for CVE 2017-11548. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-816b63ad38 2018-08-04 21:45:12.206387 --------------------------------------------------------------------------------Name : libao Product : Fedora 28 Version : 1.2.0 Release : 13.fc28 URL : https://xiph.org/ao/ Summary : Cross Platform Audio Output Library Description : Libao is a cross-platform audio library that allows programs to output audio using a simple API on a wide variety of platforms. --------------------------------------------------------------------------------Update Information: Backport fix for CVE 2017-11548 --------------------------------------------------------------------------------ChangeLog: * Tue Jul 31 2018 Adam Jackson - 1.2.0-13 - Backport fix for CVE 2017-11548 * Fri Jul 13 2018 Fedora Release Engineering - 1.2.0-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Fri Apr 6 2018 Adam Jackson - 1.2.0-11 - Update description --------------------------------------------------------------------------------References: [ 1 ] Bug #1478950 - CVE-2017-11548 libao: Invalid memory allocation in _tokenize_matrix function in audio_out.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1478950 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-816b63ad38' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announcemailing list --
Get the latest Linux and open source security news straight to your inbox.