Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update for wavpack is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: wavpack security update Advisory ID: RHSA-2022:8139-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8139 Issue date: 2022-11-15 CVE Names: CVE-2021-44269 ==================================================================== 1. Summary: An update for wavpack is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: WavPack is a completely open audio compression format providing lossless, high-quality lossy, and a unique hybrid compression mode. Security Fix(es): * wavpack: Heap out-of-bounds read in WavpackPackSamples() (CVE-2021-44269) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2064457 - CVE-2021-44269 wavpack: Heap out-of-bounds read in WavpackPackSamples() 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: wavpack-5.4.0-5.el9.src.rpm aarch64: wavpack-5.4.0-5.el9.aarch64.rpm wavpack-debuginfo-5.4.0-5.el9.aarch64.rpm wavpack-debugsource-5.4.0-5.el9.aarch64.rpm ppc64le: wavpack-5.4.0-5.el9.ppc64le.rpm wavpack-debuginfo-5.4.0-5.el9.ppc64le.rpm wavpack-debugsource-5.4.0-5.el9.ppc64le.rpm s390x: wavpack-5.4.0-5.el9.s390x.rpm wavpack-debuginfo-5.4.0-5.el9.s390x.rpm wavpack-debugsource-5.4.0-5.el9.s390x.rpm x86_64: wavpack-5.4.0-5.el9.i686.rpm wavpack-5.4.0-5.el9.x86_64.rpm wavpack-debuginfo-5.4.0-5.el9.i686.rpm wavpack-debuginfo-5.4.0-5.el9.x86_64.rpm wavpack-debugsource-5.4.0-5.el9.i686.rpm wavpack-debugsource-5.4.0-5.el9.x86_64.rpm Red Hat CodeReady Linux Builder (v. 9): aarch64: wavpack-debuginfo-5.4.0-5.el9.aarch64.rpm wavpack-debugsource-5.4.0-5.el9.aarch64.rpm wavpack-devel-5.4.0-5.el9.aarch64.rpm ppc64le: wavpack-debuginfo-5.4.0-5.el9.ppc64le.rpm wavpack-debugsource-5.4.0-5.el9.ppc64le.rpm wavpack-devel-5.4.0-5.el9.ppc64le.rpm s390x: wavpack-debuginfo-5.4.0-5.el9.s390x.rpm wavpack-debugsource-5.4.0-5.el9.s390x.rpm wavpack-devel-5.4.0-5.el9.s390x.rpm x86_64: wavpack-debuginfo-5.4.0-5.el9.i686.rpm wavpack-debuginfo-5.4.0-5.el9.x86_64.rpm wavpack-debugsource-5.4.0-5.el9.i686.rpm wavpack-debugsource-5.4.0-5.el9.x86_64.rpm wavpack-devel-5.4.0-5.el9.i686.rpm wavpack-devel-5.4.0-5.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-44269 https://access.redhat.com/security/updates/classification#low https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3PhItzjgjWX9erEAQh4rw//T/3qfrWxxg1PShfJuA9TQRkGE0azG/Fl grImhuJxDG9tviXzfEMjd7yNhWtrd1hYPF4mQqr19Rz82KXCbl8QxaSYC58zxOVG j5TZnrLYMNp/z2fIFY317JnDXy63qBkIus6BnF9mywcFsA9cLw9+YjMW1+HPlttp zn6+iIklT2IGOHWcbKODPt1Xlm6EKSHn7CSTfJvaGqjWLoA9f6wzMcTJl4w/5Gr2 8RAJjc77F8g4hu/+AMR0e2UpU8YBO8xRpua0FqyB1GIkgAJgjcWOlhBZxzJ7dFA0 9zpxHSnZJGyRHOQ+2B6AtfEFIdosHoy33ZJI4fBavvrXY4o2gtLmIEbpp8CCyjE+ 8HW1ko8+q3TiJl3F6XBRMkw9/dt8uCPfm5lCHikQS2byUUDtNaC31ko8MsB5XP8Z Y9EZJio5LP9M0nhw1nRNjcRahvcL8dHyIQvxUJ5/AwON2SZXQpyw8WdkQ/eNJt/2 nZykA5uMLPE+qQ2R9FgQbOnTPdblZNgASdq3seM/w5rMMY3MA/xaK8xf1EkMkK84 vToalSoJ994bRPsgVy15oXQuazqG4FozOVs4lKp+whGPzkEY0EWxPXKd0qGOg3Ex lZC2eenbDie2olMcyeL/ykw8djM/OBhswM/1PO2th2bksMI8e3QhB3X0mSMluK6W Y1z0TX55584=S0Wv -----END PGP SIGNATURE----- -- RHSA-announce mailing list
WavPack could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-5721-1 November 10, 2022 wavpack vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: WavPack could be made to crash if it opened a specially crafted file. Software Description: - wavpack: audio codec (lossy and lossless) - encoder and decoder Details: It was discovered that WavPack was not properly performing checks when dealing with memory. If a user were tricked into decompressing a specially crafted WavPack Audio File, an attacker could possibly use this issue to cause the WavPack decompressor to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libwavpack1 4.75.2-2ubuntu0.2+esm1 wavpack 4.75.2-2ubuntu0.2+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5721-1 CVE-2022-2476 . A security flaw in WavPack for Ubuntu may lead to system instability upon accessing specially crafted audio files, potentially triggering a denial of service scenario.. WavPack, Ubuntu, Security Update, Denial Of Service. . LinuxSecurity.com Team
An update for wavpack is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: wavpack security update Advisory ID: RHSA-2022:7558-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7558 Issue date: 2022-11-08 CVE Names: CVE-2021-44269 ==================================================================== 1. Summary: An update for wavpack is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: WavPack is a completely open audio compression format providing lossless, high-quality lossy and a unique hybrid compression mode. Security Fix(es): * wavpack: Heap out-of-bounds read in WavpackPackSamples() (CVE-2021-44269) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2064457 - CVE-2021-44269 wavpack: Heap out-of-bounds read in WavpackPackSamples() 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: wavpack-5.1.0-16.el8.src.rpm aarch64: wavpack-5.1.0-16.el8.aarch64.rpm wavpack-debuginfo-5.1.0-16.el8.aarch64.rpm wavpack-debugsource-5.1.0-16.el8.aarch64.rpm ppc64le: wavpack-5.1.0-16.el8.ppc64le.rpm wavpack-debuginfo-5.1.0-16.el8.ppc64le.rpm wavpack-debugsource-5.1.0-16.el8.ppc64le.rpm s390x: wavpack-5.1.0-16.el8.s390x.rpm wavpack-debuginfo-5.1.0-16.el8.s390x.rpm wavpack-debugsource-5.1.0-16.el8.s390x.rpm x86_64: wavpack-5.1.0-16.el8.i686.rpm wavpack-5.1.0-16.el8.x86_64.rpm wavpack-debuginfo-5.1.0-16.el8.i686.rpm wavpack-debuginfo-5.1.0-16.el8.x86_64.rpm wavpack-debugsource-5.1.0-16.el8.i686.rpm wavpack-debugsource-5.1.0-16.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v. 8): aarch64: wavpack-debuginfo-5.1.0-16.el8.aarch64.rpm wavpack-debugsource-5.1.0-16.el8.aarch64.rpm wavpack-devel-5.1.0-16.el8.aarch64.rpm ppc64le: wavpack-debuginfo-5.1.0-16.el8.ppc64le.rpm wavpack-debugsource-5.1.0-16.el8.ppc64le.rpm wavpack-devel-5.1.0-16.el8.ppc64le.rpm s390x: wavpack-debuginfo-5.1.0-16.el8.s390x.rpm wavpack-debugsource-5.1.0-16.el8.s390x.rpm wavpack-devel-5.1.0-16.el8.s390x.rpm x86_64: wavpack-debuginfo-5.1.0-16.el8.i686.rpm wavpack-debuginfo-5.1.0-16.el8.x86_64.rpm wavpack-debugsource-5.1.0-16.el8.i686.rpm wavpack-debugsource-5.1.0-16.el8.x86_64.rpm wavpack-devel-5.1.0-16.el8.i686.rpm wavpack-devel-5.1.0-16.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-44269 https://access.redhat.com/security/updates/classification#low https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.7_release_notes/index 8. Contact: The Red Hat security contact is .More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY2pSgNzjgjWX9erEAQhrBxAAmg5lBHGWNQnrrS7luwSX+m0Ags6qaan1 Ap3yK9RZhw5gTWf3LIPReWmMnMGtZ5vbwOJiHD3TIg3dV0sqNtv2kp1DC+bcYz5c jntPluyOrCtw8yq5nuaWZ9mwj/9JJ174ACXsIyqrOePhADDIfSU/EH0Sm+a3iKnU +Tb6O7vXB/ta/HhNFDRlNymCCRCO+IyWzERYOaUYcXKIqeJcLRd4nOqJuaRVbqQm PXHhl5UOspb2z1DobuzaHI4skfBNYvdHZElbaoVUDeDKN3W0x73MVGJcrCF86vmL it0lCH1jc8rZ5pRfDZP9nAzVyzJyAOAM0szTx4DCZkFZMCXIHHDR511wZnKQpZuE QDN2D6RN53BL+QbT+zm9mLy2LqdDIPvLLlVHHxgWqr1usLQPEcLvIhwspnmfwwd8 C9Macc4Bz5pJ2rUjF9W3rwHNKUUN5dbFpaVAympqWf4s4Z5CCLu2u2GO9Pm6r4u0 tXrfeV3AjRoWKVvrxyQ7r8Sl3vliSMAt3If6fxsNiUrVhRsT9PiUIIusxFTl5oQo IpELnMnJxl8Qh/X2nW4S7PMQnWBEpINRXeRZHtjrnZJW+E0ua0veOFUJXEha+BxR Pu3BUIoIzBNwL8vfPPbr0ccOjT+SyNg1H1T3ZP/5bEe0r6EGjwOPPHYmZtRiUSpX 44L6+Nf2ztg=clcE -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Security fix for CVE-2022-2476. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c9c086b06f 2022-10-22 14:34:29.731287 --------------------------------------------------------------------------------Name : wavpack Product : Fedora 35 Version : 5.5.0 Release : 2.fc35 URL : https://www.wavpack.com/ Summary : A completely open audiocodec Description : WavPack is a completely open audio compression format providing lossless, high-quality lossy, and a unique hybrid compression mode. Although the technology is loosely based on previous versions of WavPack, the new version 4 format has been designed from the ground up to offer unparalleled performance and functionality. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-2476 --------------------------------------------------------------------------------ChangeLog: * Sat Jul 23 2022 Fedora Release Engineering - 5.5.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Wed Jul 13 2022 Tomas Korbar - 5.5.0-1 - Rebase to 5.5.0 - Resolves: rhbz#2105686 --------------------------------------------------------------------------------References: [ 1 ] Bug #2110455 - CVE-2022-2476 wavpack: null pointer dereference in main() in cli/wvunpack.c https://bugzilla.redhat.com/show_bug.cgi?id=2110455 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c9c086b06f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2022-2476. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-ca2f721916 2022-10-12 13:01:12.662985 --------------------------------------------------------------------------------Name : wavpack Product : Fedora 36 Version : 5.5.0 Release : 2.fc36 URL : https://www.wavpack.com/ Summary : A completely open audiocodec Description : WavPack is a completely open audio compression format providing lossless, high-quality lossy, and a unique hybrid compression mode. Although the technology is loosely based on previous versions of WavPack, the new version 4 format has been designed from the ground up to offer unparalleled performance and functionality. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-2476 --------------------------------------------------------------------------------ChangeLog: * Sat Jul 23 2022 Fedora Release Engineering - 5.5.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Wed Jul 13 2022 Tomas Korbar - 5.5.0-1 - Rebase to 5.5.0 - Resolves: rhbz#2105686 --------------------------------------------------------------------------------References: [ 1 ] Bug #2110455 - CVE-2022-2476 wavpack: null pointer dereference in main() in cli/wvunpack.c https://bugzilla.redhat.com/show_bug.cgi?id=2110455 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-ca2f721916' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Null pointer dereference in wvunpack (CVE-2022-2476) References: - https://bugs.mageia.org/show_bug.cgi?id=30713 - https://lists.suse.com/pipermail/sle-security-updates/2022-August/011810.html . MGASA-2022-0291 - Updated wavpack packages fix security vulnerability Publication date: 20 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0291.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2476 Null pointer dereference in wvunpack (CVE-2022-2476) References: - https://bugs.mageia.org/show_bug.cgi?id=30713 - https://lists.suse.com/pipermail/sle-security-updates/2022-August/011810.html - - https://www.cve.org/CVERecord?id=CVE-2022-2476 SRPMS: - 8/core/wavpack-5.5.0-1.mga8 . The latest wavpack updates for Mageia 8 resolve a null pointer dereference issue; this is a significant security notice MGASA-2022-0291.. wavpack update, mageia security, package vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for wavpack ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2681-1 Rating: low References: #1201716 Cross-References: CVE-2022-2476 CVSS scores: CVE-2022-2476 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-2476 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for wavpack fixes the following issues: - CVE-2022-2476: Fixed a Null pointerdereference in wvunpack (bsc#1201716). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2681=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2681=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2022-2681=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP3-2022-2681=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-2681=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-2681=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): libwavpack1-5.4.0-150000.4.15.1 libwavpack1-debuginfo-5.4.0-150000.4.15.1 wavpack-5.4.0-150000.4.15.1 wavpack-debuginfo-5.4.0-150000.4.15.1 wavpack-debugsource-5.4.0-150000.4.15.1 wavpack-devel-5.4.0-150000.4.15.1 - openSUSE Leap 15.4 (x86_64): libwavpack1-32bit-5.4.0-150000.4.15.1 libwavpack1-32bit-debuginfo-5.4.0-150000.4.15.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libwavpack1-5.4.0-150000.4.15.1 libwavpack1-debuginfo-5.4.0-150000.4.15.1 wavpack-5.4.0-150000.4.15.1 wavpack-debuginfo-5.4.0-150000.4.15.1 wavpack-debugsource-5.4.0-150000.4.15.1 wavpack-devel-5.4.0-150000.4.15.1 - openSUSE Leap 15.3 (x86_64): libwavpack1-32bit-5.4.0-150000.4.15.1 libwavpack1-32bit-debuginfo-5.4.0-150000.4.15.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (aarch64 ppc64le s390x x86_64): wavpack-5.4.0-150000.4.15.1 wavpack-debuginfo-5.4.0-150000.4.15.1 wavpack-debugsource-5.4.0-150000.4.15.1 wavpack-devel-5.4.0-150000.4.15.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (aarch64 ppc64le s390x x86_64): wavpack-5.4.0-150000.4.15.1 wavpack-debuginfo-5.4.0-150000.4.15.1 wavpack-debugsource-5.4.0-150000.4.15.1 wavpack-devel-5.4.0-150000.4.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): libwavpack1-5.4.0-150000.4.15.1 libwavpack1-debuginfo-5.4.0-150000.4.15.1 wavpack-debuginfo-5.4.0-150000.4.15.1 wavpack-debugsource-5.4.0-150000.4.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libwavpack1-5.4.0-150000.4.15.1 libwavpack1-debuginfo-5.4.0-150000.4.15.1 wavpack-debuginfo-5.4.0-150000.4.15.1 wavpack-debugsource-5.4.0-150000.4.15.1 References: https://www.suse.com/security/cve/CVE-2022-2476.html https://bugzilla.suse.com/1201716 . SUSE Security Update resolves minor severity null dereference vulnerability in wavpack, including guidance for applying patches and listing of impacted products.. SUSE Linux,wavpack patch,security update,openSUSE update,update instructions. . Severity: Medium. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for wavpack ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2682-1 Rating: low References: #1201716 Cross-References: CVE-2022-2476 CVSS scores: CVE-2022-2476 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-2476 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for wavpack fixes the following issues: - CVE-2022-2476: Fixed a Null pointer dereference in wvunpack (bsc#1201716). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-2682=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-2682=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): wavpack-4.60.99-5.12.1 wavpack-debuginfo-4.60.99-5.12.1 wavpack-debugsource-4.60.99-5.12.1 wavpack-devel-4.60.99-5.12.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libwavpack1-4.60.99-5.12.1 libwavpack1-debuginfo-4.60.99-5.12.1 wavpack-debuginfo-4.60.99-5.12.1 wavpack-debugsource-4.60.99-5.12.1 References: https://www.suse.com/security/cve/CVE-2022-2476.html https://bugzilla.suse.com/1201716 . SUSE Security Update for libxml2 with Announcement ID: SUSE-SU-2022:3321-1 resolves a medium severity vulnerability.. SUSE Linux, Wavpack Security, Vulnerability Fix, Software Patch. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.