Univention Bugzilla – Bug 53626
libsndfile: Multiple issues (4.4)
Last modified: 2021-08-04 16:38:00 CEST
New Debian libsndfile 1.0.27-3+deb9u2 fixes: This update addresses the following issue: * a heap buffer overflow via crafted WAV file allows a arbitrary code execution (CVE-2021-3246)
--- mirror/ftp/4.4/unmaintained/4.4-7/source/libsndfile_1.0.27-3+deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/libsndfile_1.0.27-3+deb9u2.dsc @@ -1,3 +1,10 @@ +1.0.27-3+deb9u2 [Thu, 29 Jul 2021 19:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2021-3246 (Closes: #991496) + A crafted WAV file can trigger a heap buffer overflow and might + allow exectution of arbitrary code. + 1.0.27-3+deb9u1 [Wed, 28 Oct 2020 19:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>: * Non-maintainer upload by the LTS Team. <http://piuparts.knut.univention.de/4.4-8/#8205678131367233122>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] bdd462b5de Bug #53626: libsndfile 1.0.27-3+deb9u2 doc/errata/staging/libsndfile.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1020>