Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 822993 (CVE-2020-23903, CVE-2020-23904) - <media-libs/speex-1.2.1: multiple vulnerabilities (CVE-2020-{23903,23904})
Summary: <media-libs/speex-1.2.1: multiple vulnerabilities (CVE-2020-{23903,23904})
Status: RESOLVED FIXED
Alias: CVE-2020-23903, CVE-2020-23904
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-11-10 23:31 UTC by John Helmert III
Modified: 2022-08-16 19:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-11-10 23:31:44 UTC
CVE-2020-23903 (https://github.com/xiph/speex/issues/13):

A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

CVE-2020-23904 (https://github.com/xiph/speex/issues/14):

A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

The former has a patch merged: https://github.com/xiph/speex/commit/870ff845b32f314aec0036641ffe18aba4916887
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-16 19:14:26 UTC
Upstream says they can't reproduce the second issue, and I can't either. Let's treat that one as invalid.

The first issue is fixed in 1.2.1, and tree is clean. All done.