libsamplerate could cause a crash if it processed a specially crafted audio file.. =========================================================================Ubuntu Security Notice USN-5749-1 November 29, 2022 libsamplerate vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: libsamplerate could cause a crash if it processed a specially crafted audio file. Software Description: - libsamplerate: Audio sample rate conversion library Details: Erik de Castro Lopo and Agostino Sarubbo discovered that libsamplerate did not properly perform bounds checking. If a user were tricked into processing a specially crafted audio file, an attacker could possibly use this issue to cause a crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libsamplerate0 0.1.8-8ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5749-1 CVE-2017-7697 . Ensure your Ubuntu installation is updated to resolve vulnerabilities related to libsamplerate, which may result in system instability when processing specially designed audio files.. Ubuntu Security, Libsamplerate Risks, Audio Processing Error. . LinuxSecurity.com Team
An issue has been found in libsamplerate, an audio sample rate conversion library. Using a crafted audio file a buffer over-read might happen in calc_output_single() in src_sinc.c. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2845-1
New upstream bug fix release. This version includes a fix for CVE-2017-7697.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2012089e37 2018-03-06 17:26:39.510257 --------------------------------------------------------------------------------Name : libsamplerate Product : Fedora 26 Version : 0.1.9 Release : 1.fc26 URL : http://www.mega-nerd.com/SRC/ Summary : Sample rate conversion library for audio data Description : Secret Rabbit Code is a sample rate converter for audio. It is capable of arbitrary and time varying conversions. It can downsample by a factor of 12 and upsample by the same factor. The ratio of input and output sample rates can be a real number. The conversion ratio can also vary with time for speeding up and slowing down effects. --------------------------------------------------------------------------------Update Information: New upstream bug fix release. This version includes a fix for CVE-2017-7697. --------------------------------------------------------------------------------References: [ 1 ] Bug #1441644 - CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1441644 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libsamplerate' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New upstream bug fix release. This version includes a fix for CVE-2017-7697.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2012089e37 2018-03-06 17:26:39.510257 --------------------------------------------------------------------------------Name : libsamplerate Product : Fedora 26 Version : 0.1.9 Release : 1.fc26 URL : http://www.mega-nerd.com/SRC/ Summary : Sample rate conversion library for audio data Description : Secret Rabbit Code is a sample rate converter for audio. It is capable of arbitrary and time varying conversions. It can downsample by a factor of 12 and upsample by the same factor. The ratio of input and output sample rates can be a real number. The conversion ratio can also vary with time for speeding up and slowing down effects. --------------------------------------------------------------------------------Update Information: New upstream bug fix release. This version includes a fix for CVE-2017-7697. --------------------------------------------------------------------------------References: [ 1 ] Bug #1441644 - CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1441644 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libsamplerate' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New upstream bug fix release. This version includes a fix for CVE-2017-7697.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-418e67c843 2018-02-27 17:16:42.082732 --------------------------------------------------------------------------------Name : libsamplerate Product : Fedora 27 Version : 0.1.9 Release : 1.fc27 URL : http://www.mega-nerd.com/SRC/ Summary : Sample rate conversion library for audio data Description : Secret Rabbit Code is a sample rate converter for audio. It is capable of arbitrary and time varying conversions. It can downsample by a factor of 12 and upsample by the same factor. The ratio of input and output sample rates can be a real number. The conversion ratio can also vary with time for speeding up and slowing down effects. --------------------------------------------------------------------------------Update Information: New upstream bug fix release. This version includes a fix for CVE-2017-7697. --------------------------------------------------------------------------------References: [ 1 ] Bug #1441644 - CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1441644 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libsamplerate' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A buffer overflow vulnerability in libsamplerate might lead to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200812-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libsamplerate: User-assisted execution of arbitrary code Date: December 02, 2008 Bugs: #237037 ID: 200812-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow vulnerability in libsamplerate might lead to the execution of arbitrary code. Background ========= Secret Rabbit Code (aka libsamplerate) is a Sample Rate Converter for audio. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libsamplerate < 0.1.4 > = 0.1.4 Description ========== Russell O'Connor reported a buffer overflow in src/src_sinc.c related to low conversion ratios. Impact ===== A remote attacker could entice a user or automated system to process a specially crafted audio file possibly leading to the execution of arbitrary code with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All libsamplerate users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =media-libs/libsamplerate-0.1.4" References ========= [ 1 ] CVE-2008-5008 https://www.cve.org/CVERecord?id=CVE-2008-5008 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200812-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.