MGASA-2024-0373 - Updated libsndfile packages fix security vulnerability

Publication date: 27 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0373.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-50612

libsndfile suffers from an out-of-bounds read in ogg_vorbis.c
vorbis_analysis_wrote.

References:
- https://bugs.mageia.org/show_bug.cgi?id=33789
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PYXWUCWTDAITTQHM72BGA2ENVXC7G5M/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50612

SRPMS:
- 9/core/libsndfile-1.2.0-3.2.mga9

Mageia 2024-0373: libsndfile Security Advisory Updates

libsndfile suffers from an out-of-bounds read in ogg_vorbis.c vorbis_analysis_wrote

Summary

libsndfile suffers from an out-of-bounds read in ogg_vorbis.c vorbis_analysis_wrote.

References

- https://bugs.mageia.org/show_bug.cgi?id=33789

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PYXWUCWTDAITTQHM72BGA2ENVXC7G5M/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50612

Resolution

MGASA-2024-0373 - Updated libsndfile packages fix security vulnerability

SRPMS

- 9/core/libsndfile-1.2.0-3.2.mga9

Severity
Publication date: 27 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0373.html
Type: security
CVE: CVE-2024-50612

Related News