An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for opusfile ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0013-1 Rating: moderate References: #1207381 Cross-References: CVE-2022-47021 CVSS scores: CVE-2022-47021 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for opusfile fixes the following issues: - CVE-2022-47021: Fixed a NULL pointer dereference (boo#1207381) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-13=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): libopusfile0-0.12-bp155.3.3.1 libopusfile0-debuginfo-0.12-bp155.3.3.1 opusfile-debugsource-0.12-bp155.3.3.1 opusfile-devel-0.12-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-47021.html https://bugzilla.suse.com/1207381 . An update fixes the NULL pointer dereference vulnerability in libopusfile for openSUSE, enhancing security measures.. openSUSE Security, Opusfile Update, Moderate Security Fix, Linux Patch Management, System Vulnerability. . LinuxSecurity.com Team
Add upstream fix for CVE-2022-47021. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-6b83109e4e 2023-02-10 01:24:19.202167 --------------------------------------------------------------------------------Name : opusfile Product : Fedora 36 Version : 0.12 Release : 9.fc36 URL : https://www.opus-codec.org/ Summary : A high-level API for decoding and seeking within .opus files Description : libopusfile provides a high-level API for decoding and seeking within .opus files. It includes: * Support for all files with at least one Opus stream (including multichannel files or Ogg files where Opus is muxed with something else). * Full support, including seeking, for chained files. * A simple stereo downmixing API (allowing chained files to be decoded with a single output format, even if the channel count changes). * Support for reading from a file, memory buffer, or over HTTP(S) (including seeking). * Support for both random access and streaming data sources. --------------------------------------------------------------------------------Update Information: Add upstream fix for CVE-2022-47021 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 1 2023 Peter Robinson - 0.12-9 - Add upstream fix for CVE-2022-47021 * Thu Jan 19 2023 Fedora Release Engineering - 0.12-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Fri Jul 22 2022 Fedora Release Engineering - 0.12-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2163902 - CVE-2022-47021 opusfile: NULL pointer dereference in op_get_data() and op_open1() in opusfile.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2163902 --------------------------------------------------------------------------------This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6b83109e4e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
NULL pointer dereferences in op_get_data() and op_open1() in opusfile.c (CVE-2022-47021) References: - https://bugs.mageia.org/show_bug.cgi?id=31505 . MGASA-2023-0042 - Updated opusfile packages fix security vulnerability Publication date: 07 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0042.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-47021 NULL pointer dereferences in op_get_data() and op_open1() in opusfile.c (CVE-2022-47021) References: - https://bugs.mageia.org/show_bug.cgi?id=31505 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.