Mageia 2018-0462: soundtouch security update
Summary
Assertion failure in BPMDetect class in BPMDetect.cpp (CVE-2018-17096).
Out-of-bounds heap write in WavOutFile::write() (CVE-2018-17097).
Heap corruption in WavFileBase class in WavFile.cpp (CVE-2018-17098).
References
- https://bugs.mageia.org/show_bug.cgi?id=23823
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-17096
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-17097
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-17098
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17096
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17097
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17098
Resolution
MGASA-2018-0462 - Updated soundtouch packages fix security vulnerabilities
SRPMS
- 6/core/soundtouch-2.1.1-1.mga6