New Debian libsndfile 1.0.28-6+deb10u1 fixes: This update addresses the following issue: * a heap buffer overflow via crafted WAV file allows a arbitrary code execution (CVE-2021-3246)
--- mirror/ftp/pool/main/libs/libsndfile/libsndfile_1.0.28-6.dsc +++ apt/ucs_5.0-0-errata5.0-0/source/libsndfile_1.0.28-6+deb10u1.dsc @@ -1,3 +1,7 @@ +1.0.28-6+deb10u1 [Fri, 30 Jul 2021 00:14:25 +0200] Moritz Mühlenhoff <jmm@debian.org>: + + * CVE-021-3246 (Closes: #991496) + 1.0.28-6 [Fri, 08 Mar 2019 20:35:07 +0100] IOhannes m zmölnig (Debian/GNU) <umlaeute@debian.org>: * Backported fix for out-of-bound reading (CVE-2019-3832) (Closes: #922372) <http://piuparts.knut.univention.de/5.0-0/#4569528372505931026>
OK: yaml OK: announce_errata OK: patch OK: piuparts
<https://errata.software-univention.de/#/?erratum=5.0x60>