An update for speex is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: speex security update Advisory ID: RHSA-2022:7979-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7979 Issue date: 2022-11-15 CVE Names: CVE-2020-23903 ==================================================================== 1. Summary: An update for speex is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: Speex is a patent-free compression format designed especially for speech. It is specialized for voice communications at low bit-rates. Security Fix(es): * speex: divide by zero in read_samples() via crafted WAV file (CVE-2020-23903) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2024250 - CVE-2020-23903 speex: divide by zero in read_samples() via crafted WAV file 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: speex-1.2.0-11.el9.src.rpm aarch64: speex-1.2.0-11.el9.aarch64.rpm speex-debuginfo-1.2.0-11.el9.aarch64.rpm speex-debugsource-1.2.0-11.el9.aarch64.rpm speex-tools-debuginfo-1.2.0-11.el9.aarch64.rpm ppc64le: speex-1.2.0-11.el9.ppc64le.rpm speex-debuginfo-1.2.0-11.el9.ppc64le.rpm speex-debugsource-1.2.0-11.el9.ppc64le.rpm speex-tools-debuginfo-1.2.0-11.el9.ppc64le.rpm s390x: speex-1.2.0-11.el9.s390x.rpm speex-debuginfo-1.2.0-11.el9.s390x.rpm speex-debugsource-1.2.0-11.el9.s390x.rpm speex-tools-debuginfo-1.2.0-11.el9.s390x.rpm x86_64: speex-1.2.0-11.el9.i686.rpm speex-1.2.0-11.el9.x86_64.rpm speex-debuginfo-1.2.0-11.el9.i686.rpm speex-debuginfo-1.2.0-11.el9.x86_64.rpm speex-debugsource-1.2.0-11.el9.i686.rpm speex-debugsource-1.2.0-11.el9.x86_64.rpm speex-tools-debuginfo-1.2.0-11.el9.i686.rpm speex-tools-debuginfo-1.2.0-11.el9.x86_64.rpm Red Hat CodeReady Linux Builder (v. 9): aarch64: speex-debuginfo-1.2.0-11.el9.aarch64.rpm speex-debugsource-1.2.0-11.el9.aarch64.rpm speex-devel-1.2.0-11.el9.aarch64.rpm speex-tools-debuginfo-1.2.0-11.el9.aarch64.rpm ppc64le: speex-debuginfo-1.2.0-11.el9.ppc64le.rpm speex-debugsource-1.2.0-11.el9.ppc64le.rpm speex-devel-1.2.0-11.el9.ppc64le.rpm speex-tools-debuginfo-1.2.0-11.el9.ppc64le.rpm s390x: speex-debuginfo-1.2.0-11.el9.s390x.rpm speex-debugsource-1.2.0-11.el9.s390x.rpm speex-devel-1.2.0-11.el9.s390x.rpm speex-tools-debuginfo-1.2.0-11.el9.s390x.rpm x86_64: speex-debuginfo-1.2.0-11.el9.i686.rpm speex-debuginfo-1.2.0-11.el9.x86_64.rpm speex-debugsource-1.2.0-11.el9.i686.rpm speex-debugsource-1.2.0-11.el9.x86_64.rpm speex-devel-1.2.0-11.el9.i686.rpm speex-devel-1.2.0-11.el9.x86_64.rpm speex-tools-debuginfo-1.2.0-11.el9.i686.rpm speex-tools-debuginfo-1.2.0-11.el9.x86_64.rpm These packages are GPG signed by Red Hat forsecurity. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-23903 https://access.redhat.com/security/updates/classification#low https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3OMedzjgjWX9erEAQgS4RAAi26Dt98tqjcq7pMiIWB2VwDQlgkFrgug Ux1A9jpIypUQKBuxEbfruJlPJJvNjhDnhiMhJL3cLsI17pNdw+Q9lvgYDEtHvjw5 WtupnQIPEWArzpRMtk6FlIBZarncGjPNBcsXtOz8yeu9fqeQ6MmfiyFpq7OFr8H4 EzTnEXmkVyhUYj/DTUAD1eKk5TqKsvh7vOp3tt1lgQQOvGFNkx9rVGtry65MO6pb TRAdDn4FTfoPWZAcVFH2CxsU9Ob0oHziTB1wqACUPJVRaMfJMBUEj1/T8nzLSAbX drkp3Zyk503Fx7vazP8Rllc4xHZlnpKsR6Pr/Thi5Vc6wfBePGRIopMRzEgOxP2C vpvCCQ70wW0nAh04xp4syDvTUW35DSApYB/yjw8xeNsyN+2tMqPRK//k8KSkFa9/ X+g/Ey8Z06U5KQ1yWBNgKMoRmXA5zfXtLS9lS9ArXtAeripa/gLhl4cHcUxnU1W5 IxlfhIqSnHSHIFumm77W9vmRmYojlvtQGvZPO2wGmoiID16xB+LwUWNiqOJLqi5z M3GX6nt9trzpnJqyGLTfW0vr7xpY8fDL2GZaAsngkQRTOFsdonF0wmjUZPEFo7Se wIVKQjhljfdceibYUk7jdSFnDulX+VQOyBgWgp+EaJuwdt0NzW7LcXfFxCI/1eRp whTtb7CD4wM=7XMZ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Speex could be made to denial of service if it received a specially crafted WAV file.. =========================================================================Ubuntu Security Notice USN-5280-1 February 10, 2022 speex vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: Speex could be made to denial of service if it received a specially crafted WAV file. Software Description: - speex: The Speex codec command line tools Details: It was discovered that Speex incorrectly handled certain WAV files. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: speex 1.2~rc1.2-1.1ubuntu1.21.10.1 Ubuntu 20.04 LTS: speex 1.2~rc1.2-1.1ubuntu1.20.04.1 Ubuntu 18.04 LTS: speex 1.2~rc1.2-1ubuntu2.1 Ubuntu 16.04 ESM: speex 1.2~rc1.2-1ubuntu1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5280-1 CVE-2020-23903 Package Information: https://launchpad.net/ubuntu/+source/speex/1.2~rc1.2-1.1ubuntu1.21.10.1 https://launchpad.net/ubuntu/+source/speex/1.2~rc1.2-1.1ubuntu1.20.04.1 https://launchpad.net/ubuntu/+source/speex/1.2~rc1.2-1ubuntu2.1 . Uncover significant vulnerability in Speex on Ubuntu impacting various editions, with insights on patches and remedies.. Ubuntu Security, Speex Denial of Service, Software Update. . Severity: Critical. LinuxSecurity.com Team
Fixed zero division error in read_samples (bsc#1192580). (CVE-2020-23903) References: - https://bugs.mageia.org/show_bug.cgi?id=29718 - https://lists.suse.com/pipermail/sle-security-updates/2021-December/009798.html . MGASA-2021-0550 - Updated speex packages fix security vulnerability Publication date: 10 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0550.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-23903 Fixed zero division error in read_samples (bsc#1192580). (CVE-2020-23903) References: - https://bugs.mageia.org/show_bug.cgi?id=29718 - https://lists.suse.com/pipermail/sle-security-updates/2021-December/009798.html - - https://lists.fedoraproject.org/archives/list/
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for speex ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1538-1 Rating: moderate References: #1192580 Cross-References: CVE-2020-23903 CVSS scores: CVE-2020-23903 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for speex fixes the following issues: - CVE-2020-23903: Fixed zero division error in read_samples (bsc#1192580). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-1538=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): libspeex1-1.2-lp152.4.3.1 libspeex1-debuginfo-1.2-lp152.4.3.1 speex-1.2-lp152.4.3.1 speex-debuginfo-1.2-lp152.4.3.1 speex-debugsource-1.2-lp152.4.3.1 speex-devel-1.2-lp152.4.3.1 - openSUSE Leap 15.2 (x86_64): libspeex1-32bit-1.2-lp152.4.3.1 libspeex1-32bit-debuginfo-1.2-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-23903.html https://bugzilla.suse.com/1192580 . Patch released for openSUSE rectifies moderate security flaw in speex, handling zero division exceptions. Refer to the advisory for comprehensive information.. openSUSE Security Update, Speex Patch, Vulnerability Fix. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for speex ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:3860-1 Rating: moderate References: #1192580 Cross-References: CVE-2020-23903 CVSS scores: CVE-2020-23903 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for speex fixes the following issues: - CVE-2020-23903: Fixed zero division error in read_samples (bsc#1192580). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-3860=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libspeex1-1.2-3.3.1 libspeex1-debuginfo-1.2-3.3.1 speex-1.2-3.3.1 speex-debuginfo-1.2-3.3.1 speex-debugsource-1.2-3.3.1 speex-devel-1.2-3.3.1 - openSUSE Leap 15.3 (x86_64): libspeex1-32bit-1.2-3.3.1 libspeex1-32bit-debuginfo-1.2-3.3.1 References: https://www.suse.com/security/cve/CVE-2020-23903.html https://bugzilla.suse.com/1192580 . The latest Debian upgrade fixes a critical OpenSSL vulnerability, enhancing overall security. Immediate application of this update is recommended.. openSUSE Security Update, Speex Fix, Moderate Advisory. . LinuxSecurity.com Team
It was discovered that speex, The Speex codec command line tools, did not correctly did not correctly deal with negative offsets in a particular header field. This could allow a malicious file to execute arbitrary code.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1585-1
It was discovered that Speex did not properly validate its input when processing Speex file headers. If a user or automated system were tricked into opening a specially crafted Speex file, an attacker could create a denial of service in applications linked against Speex or possibly execute arbitrary code as the user invoking the program. . =========================================================== Ubuntu Security Notice USN-611-1 May 08, 2008 speex vulnerability CVE-2008-1686 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.04 Ubuntu 7.10 Ubuntu 8.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libspeex1 1.1.11.1-1ubuntu0.3 Ubuntu 7.04: libspeex1 1.1.12-3ubuntu0.7.04.1 Ubuntu 7.10: libspeex1 1.1.12-3ubuntu0.7.10.1 Ubuntu 8.04 LTS: libspeex1 1.1.12-3ubuntu0.8.04.1 After a standard system upgrade you need to restart applications linked against Speex to effect the necessary changes. Details follow: It was discovered that Speex did not properly validate its input when processing Speex file headers. If a user or automated system were tricked into opening a specially crafted Speex file, an attacker could create a denial of service in applications linked against Speex or possibly execute arbitrary code as the user invoking the program. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 16334 3043ac1b83c4f616ee9e7ce0445f6f4a Size/MD5: 891 a47ed95c32a7f46195117b0940003512 Size/MD5: 720528 5282d23ea605232be05b537cca7af242 Architecture independent packages: Size/MD5: 1175164 88a00eb0263c884a7fb2f8e86f7085cf amd64architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 99344 ff9c32a2add83695f263ab665bfeea2e Size/MD5: 73114 fb8d379b7b59a01dfbdc71061ec55d2f Size/MD5: 25730 3024d74692a5284a7d3c3c7a0ea731f4 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 85844 103f5455a185b5f7b67e1e9db8e09bf5 Size/MD5: 68198 e49b7fcbe1dac385ea3dd3531b3578ab Size/MD5: 24506 f313ba989a11acfc1d087f0cbf32ec1c powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 102896 6f060fc21867cb58ebbc2bc2610a89e4 Size/MD5: 78074 139b3f33a76ace71235795c5a5d5c257 Size/MD5: 27502 9abaa0c5f9c85fc61bf7dbae3c367b24 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 93950 60cd3a6214b4131804e04ef726512706 Size/MD5: 72626 3bc63bc48594cfb32dba17c63c9278a1 Size/MD5: 25564 f44fac017d8f1cad870b8b7d865ae704 Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 16462 8f5c4ba40a9d55f67207def20fd0d8f8 Size/MD5: 896 bf22d92d6a3d9e152c7e3d8e5516e5aa Size/MD5: 740110 1bd6cdf3a0ebabf818cd72a3401e2610 Architecture independent packages: Size/MD5: 1621198 e693f69bee4af4022f1426628d8fa874 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 107898 ca461c3a1137db04b701f6abf359221c Size/MD5: 81248 63a3b920764b3c7a8c440ece3d5a6628 Size/MD5: 26278 1e0bb2a94c4f8cb9d7b8a879c87d77a5 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 93276 3fc302a1d7250759c05cdb9266795512 Size/MD5: 76948 54b210c5e9aa7165b2e3574d4ec22129 Size/MD5: 25348 d40840a2b30852980cb8abe33f8f52b4 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 111304 fecf9674ed877ee012d4481dbfd28ff7 Size/MD5: 88048 dea6b4205ec628871f6ff16eaf50c2f1 Size/MD5: 298605925a4f45f770f209fff316f78dba6cc sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 100622 b4f79870679d10a746122d62824520a5 Size/MD5: 79974 363d994497fbe56da99c9e3d190159aa Size/MD5: 26626 17839bcc3c1c7f8e093527a9b012b5c1 Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 16464 a9f2cc5874334105f139fe4658d6932a Size/MD5: 896 19296f16fadc226b5bfa661c5c60446a Size/MD5: 740110 1bd6cdf3a0ebabf818cd72a3401e2610 Architecture independent packages: Size/MD5: 2739332 950760db17a4a3ddd98819b664e2cade amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 108820 fb59780481a14fd71d7404dcbd468de2 Size/MD5: 81928 26a27b1731508bcbcf30927f016deb13 Size/MD5: 26320 e0d3ddab4c85093e3510f724bad4328a i386 architecture (x86 compatible Intel/AMD): Size/MD5: 93644 b36263803f01174d6bb1577064aa3528 Size/MD5: 77590 d0e00ef79d2c4ee88815cebcd327b73a Size/MD5: 25242 d34367d6b1842d636d3cd7e184c4fb3c lpia architecture (Low Power Intel Architecture): Size/MD5: 92996 b875296d5217f2102f5d3913a11856a2 Size/MD5: 76334 8b44f386012576e364aa5051cb496c29 Size/MD5: 25432 a38ad81fba60b956968e54722ff82dcc powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 111450 d505aff351cb6b59dfa101b7fe902443 Size/MD5: 88112 e06e4db8125927e9078742bfaba8e56c Size/MD5: 29808 798c8763dbecb9d00234aca8f29ce4ee sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 100846 715db8b55820a946decb096afff83cc7 Size/MD5: 80278 0ef531ecf94d3f86bd0b262625f7f046 Size/MD5: 26644 0bbb348bd1845c929bac9060c17c3440 Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 16463 ffe6236efeb0636cf1bb82e35e62040c Size/MD5: 896 4b325c8f915dccda407ecd3d9674d227 Size/MD5: 740110 1bd6cdf3a0ebabf818cd72a3401e2610 Architecture independent packages: Size/MD5: 1374930 cff30859bb6d6d297eb0a67bb1ed4a68 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 107162 d2cca372509a36921f7df4c6d91764c4 Size/MD5: 80596 0474f2424b6ef876744af59abf9a3b9e Size/MD5: 26366 6738274b4274e17566979a13dd8f00e2 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 92798 ce4b30f29cb5251fa9646d2c51d0ad5b Size/MD5: 75300 85cf718906c94e92f7abf54233610779 Size/MD5: 25470 1f49095ca5a425fbf0bcafd3bf61deae lpia architecture (Low Power Intel Architecture): Size/MD5: 93058 7c59131c5b33638da73ce607443af0f3 Size/MD5: 75470 142296715793d59b602509996b012386 Size/MD5: 25448 fb2e0288d95179ddcd381b90ed51ed74 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 110910 aec0ff1c13d10e5a4240e9e228e17476 Size/MD5: 85722 99aa4c03960bc31c1aa11b5c6dd3b78c Size/MD5: 30130 fae12b25bb03ead975f0717a9a9ccf4f sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 100536 bbe537676e242db9d9f032327a4ef82f Size/MD5: 79398 101308f94e0dcb27bd429eaab076927e Size/MD5: 26430 4203e6d8b4f6612d0ed2250a84970820 . Ubuntu Security Advisory USN-612-1 tackles a critical libxml2 vulnerability, mitigating buffer overflow dangers and potential exploitation threats.. Speex Vulnerability, Denial Of Service, Input Validation, Ubuntu Security. . Severity: Important. LinuxSecurity.com Team
Important: speex security update. Date: Thu, 17 Apr 2008 14:27:48 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for speex on SL4.x, SL5.x i386/x86_64 Comments: To: "
Get the latest Linux and open source security news straight to your inbox.