Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
172

Ubuntu 16.04 ESM USN-5749-1 Moderate: Libsamplerate Crash Threat

libsamplerate could cause a crash if it processed a specially crafted audio file.. =========================================================================Ubuntu Security Notice USN-5749-1 November 29, 2022 libsamplerate vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: libsamplerate could cause a crash if it processed a specially crafted audio file. Software Description: - libsamplerate: Audio sample rate conversion library Details: Erik de Castro Lopo and Agostino Sarubbo discovered that libsamplerate did not properly perform bounds checking. If a user were tricked into processing a specially crafted audio file, an attacker could possibly use this issue to cause a crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libsamplerate0 0.1.8-8ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5749-1 CVE-2017-7697 . Ensure your Ubuntu installation is updated to resolve vulnerabilities related to libsamplerate, which may result in system instability when processing specially designed audio files.. Ubuntu Security, Libsamplerate Risks, Audio Processing Error. . LinuxSecurity.com Team

Calendar 2 Nov 29, 2022 Ubuntu
197

Debian 9 Stretch: DLA-2845-1 Critical: libsamplerate Buffer Overflow

An issue has been found in libsamplerate, an audio sample rate conversion library. Using a crafted audio file a buffer over-read might happen in calc_output_single() in src_sinc.c. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2845-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz December 14, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libsamplerate Version : 0.1.8-8+deb9u1 CVE ID : CVE-2017-7697 An issue has been found in libsamplerate, an audio sample rate conversion library. Using a crafted audio file a buffer over-read might happen in calc_output_single() in src_sinc.c. For Debian 9 stretch, this problem has been fixed in version 0.1.8-8+deb9u1. We recommend that you upgrade your libsamplerate packages. For the detailed security status of libsamplerate please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libsamplerate Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical patch released for heap overflow vulnerability in libcompress audio toolkit on Ubuntu 20.04 Focal. Upgrade immediately!. Debian Security Update, libsamplerate Buffer Overflow, Debian LTS. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 13, 2021 Critical Debian LTS
89

Fedora 27: FEDORA-2019-4b0f1e4202 Critical: libjpeg-turbo Memory Leak

New upstream bug fix release. This version includes a fix for CVE-2017-7697.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2012089e37 2018-03-06 17:26:39.510257 --------------------------------------------------------------------------------Name : libsamplerate Product : Fedora 26 Version : 0.1.9 Release : 1.fc26 URL : http://www.mega-nerd.com/SRC/ Summary : Sample rate conversion library for audio data Description : Secret Rabbit Code is a sample rate converter for audio. It is capable of arbitrary and time varying conversions. It can downsample by a factor of 12 and upsample by the same factor. The ratio of input and output sample rates can be a real number. The conversion ratio can also vary with time for speeding up and slowing down effects. --------------------------------------------------------------------------------Update Information: New upstream bug fix release. This version includes a fix for CVE-2017-7697. --------------------------------------------------------------------------------References: [ 1 ] Bug #1441644 - CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1441644 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libsamplerate' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an emailto This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu 18.04 patches OpenSSL to address vulnerability CVE-2018-0732, enhancing the safety and efficiency of encrypted communications.. libsamplerate Update, Software Security, Buffer Overflow, Fedora Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 06, 2018 Critical Fedora
89

Fedora 26: FEDORA-2018-2012089e37 Moderate: libsamplerate Buffer Overflow

New upstream bug fix release. This version includes a fix for CVE-2017-7697.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2012089e37 2018-03-06 17:26:39.510257 --------------------------------------------------------------------------------Name : libsamplerate Product : Fedora 26 Version : 0.1.9 Release : 1.fc26 URL : http://www.mega-nerd.com/SRC/ Summary : Sample rate conversion library for audio data Description : Secret Rabbit Code is a sample rate converter for audio. It is capable of arbitrary and time varying conversions. It can downsample by a factor of 12 and upsample by the same factor. The ratio of input and output sample rates can be a real number. The conversion ratio can also vary with time for speeding up and slowing down effects. --------------------------------------------------------------------------------Update Information: New upstream bug fix release. This version includes a fix for CVE-2017-7697. --------------------------------------------------------------------------------References: [ 1 ] Bug #1441644 - CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1441644 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libsamplerate' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest libsamplerate update in Fedora 26 addresses the CVE-2017-7698 vulnerability related to buffer overflow. Upgrade now to bolster your system's security.. libsamplerate Update,Fedora Security,Bug Fix,Buffer Overflow,Software Release. . LinuxSecurity.com Team

Calendar 2 Mar 06, 2018 Fedora
89

Fedora 29: FEDORA-2019-5b2d670512 Urgent: libmymodule Memory Corruption

New upstream bug fix release. This version includes a fix for CVE-2017-7697.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-418e67c843 2018-02-27 17:16:42.082732 --------------------------------------------------------------------------------Name : libsamplerate Product : Fedora 27 Version : 0.1.9 Release : 1.fc27 URL : http://www.mega-nerd.com/SRC/ Summary : Sample rate conversion library for audio data Description : Secret Rabbit Code is a sample rate converter for audio. It is capable of arbitrary and time varying conversions. It can downsample by a factor of 12 and upsample by the same factor. The ratio of input and output sample rates can be a real number. The conversion ratio can also vary with time for speeding up and slowing down effects. --------------------------------------------------------------------------------Update Information: New upstream bug fix release. This version includes a fix for CVE-2017-7697. --------------------------------------------------------------------------------References: [ 1 ] Bug #1441644 - CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1441644 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libsamplerate' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an emailto This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolution for severe libsamplerate buffer overflow in Fedora 27. Upgrade implemented to improve audio handling security.. libsamplerate Security,Fedora Updates,Buffer Overflow Fix,Audio Processing Software,Upstream Bug Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 27, 2018 Important Fedora
91

Gentoo: 200812-05 Normal: Libsamplerate Buffer Overflow Threat

A buffer overflow vulnerability in libsamplerate might lead to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200812-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libsamplerate: User-assisted execution of arbitrary code Date: December 02, 2008 Bugs: #237037 ID: 200812-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow vulnerability in libsamplerate might lead to the execution of arbitrary code. Background ========= Secret Rabbit Code (aka libsamplerate) is a Sample Rate Converter for audio. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libsamplerate < 0.1.4 > = 0.1.4 Description ========== Russell O'Connor reported a buffer overflow in src/src_sinc.c related to low conversion ratios. Impact ===== A remote attacker could entice a user or automated system to process a specially crafted audio file possibly leading to the execution of arbitrary code with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All libsamplerate users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =media-libs/libsamplerate-0.1.4" References ========= [ 1 ] CVE-2008-5008 https://www.cve.org/CVERecord?id=CVE-2008-5008 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200812-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A vulnerability in libsoundfile on Arch Linux could allow for remote code execution. Updating the software is one method to resolve the issue.. libsamplerate, buffer overflow, arbitrary code execution, gentoo security, advisory update. . LinuxSecurity.com Team

Calendar 2 Dec 02, 2008 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here