Description: "An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 8 case."
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e804cebc451219555e782a2bb4f52090486d808a commit e804cebc451219555e782a2bb4f52090486d808a Author: John Helmert III <jchelmert3@posteo.net> AuthorDate: 2021-01-07 16:57:26 +0000 Commit: Miroslav Šulc <fordfrog@gentoo.org> CommitDate: 2021-01-08 09:51:03 +0000 media-libs/faac: security cleanup (drop <1.30) Bug: https://bugs.gentoo.org/762505 Package-Manager: Portage-3.0.12, Repoman-3.0.2 Signed-off-by: John Helmert III <jchelmert3@posteo.net> Signed-off-by: Miroslav Šulc <fordfrog@gentoo.org> media-libs/faac/Manifest | 1 - media-libs/faac/faac-1.29.9.2.ebuild | 36 ------------------------------------ 2 files changed, 37 deletions(-)
the tree is clean, you can proceed.
Package list is empty or all packages have requested keywords.
Request filed.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=ac47adfe629ab40cef7f5405eb0f81e15a2f6336 commit ac47adfe629ab40cef7f5405eb0f81e15a2f6336 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2022-08-10 22:30:58 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2022-08-10 22:33:18 +0000 [ GLSA 202208-16 ] faac: Denial of service Bug: https://bugs.gentoo.org/762505 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202208-16.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+)
GLSA released, all done!