security advisorybuffer overflowdebian
Several vulnerabilities were fixed in MilkyTracker, a music tracker for composing music in the MOD and XM module file formats. CVE-2019-14464 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2292-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ July 27, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : milkytracker Version : 0.90.86+dfsg-2+deb9u1 CVE ID : CVE-2019-14464 CVE-2019-14496 CVE-2019-14497 CVE-2020-15569 Debian Bug : 933964 964797 Several vulnerabilities were fixed in MilkyTracker, a music tracker for composing music in the MOD and XM module file formats. CVE-2019-14464 Heap-based buffer overflow in XMFile::read CVE-2019-14496 Stack-based buffer overflow in LoaderXM::load CVE-2019-14497 Heap-based buffer overflow in ModuleEditor::convertInstrument CVE-2020-15569 Use-after-free in the PlayerGeneric destructor For Debian 9 stretch, these problems have been fixed in version 0.90.86+dfsg-2+deb9u1. We recommend that you upgrade your milkytracker packages. For the detailed security status of milkytracker please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/milkytracker Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS announcement DLA-2293-1 upgrades VLC Media Player to rectify various integer overflows and security vulnerabilities.. MilkyTracker, Debian LTS, security update, buffer overflow, music composing. . Severity: Critical. LinuxSecurity.com Team
Jul 27, 2020
•Critical
Debian LTS