Summary: | <media-libs/libsndfile-1.0.26: buffer overread (CVE-2014-9496) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | sound |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2014/12/25/2 | ||
Whiteboard: | B2 [glsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 566680 | ||
Bug Blocks: |
Description
Agostino Sarubbo
2014-12-28 09:33:04 UTC
CVE-2014-9496 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9496): The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read. commit 6f4d6d4e5f9402581ccb90dcba045a509b03a99a Author: Justin Lecher <jlec@gentoo.org> Date: Tue Jan 26 09:51:14 2016 +0100 media-libs/libsndfile: Drop version vulnerable for CVE-2015-7805 Package-Manager: portage-2.2.27 Signed-off-by: Justin Lecher <jlec@gentoo.org> https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6f4d6d4e5f9402581ccb90dcba045a509b03a99a @sec, clean again @ Security: Waiting for GLSA... This issue was resolved and addressed in GLSA 201612-03 at https://security.gentoo.org/glsa/201612-03 by GLSA coordinator Aaron Bauman (b-man). |