-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Low: libvorbis security update
Advisory ID:       RHSA-2019:3703-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2019:3703
Issue date:        2019-11-05
CVE Names:         CVE-2018-10392 CVE-2018-10393 
====================================================================
1. Summary:

An update for libvorbis is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact
of Low. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64

3. Description:

The libvorbis package contains runtime libraries for use in programs that
support Ogg Vorbis, a fully open, non-proprietary, patent- and
royalty-free, general-purpose compressed format for audio and music at
fixed and variable bitrates.

Security Fix(es):

* libvorbis: heap buffer overflow in mapping0_forward function
(CVE-2018-10392)

* libvorbis: stack buffer overflow in bark_noise_hybridmp function
(CVE-2018-10393)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.1 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1574193 - CVE-2018-10392 libvorbis: heap buffer overflow in mapping0_forward function
1574194 - CVE-2018-10393 libvorbis: stack buffer overflow in bark_noise_hybridmp function

6. Package List:

Red Hat Enterprise Linux AppStream (v. 8):

Source:
libvorbis-1.3.6-2.el8.src.rpm

aarch64:
libvorbis-1.3.6-2.el8.aarch64.rpm
libvorbis-debuginfo-1.3.6-2.el8.aarch64.rpm
libvorbis-debugsource-1.3.6-2.el8.aarch64.rpm

ppc64le:
libvorbis-1.3.6-2.el8.ppc64le.rpm
libvorbis-debuginfo-1.3.6-2.el8.ppc64le.rpm
libvorbis-debugsource-1.3.6-2.el8.ppc64le.rpm

s390x:
libvorbis-1.3.6-2.el8.s390x.rpm
libvorbis-debuginfo-1.3.6-2.el8.s390x.rpm
libvorbis-debugsource-1.3.6-2.el8.s390x.rpm

x86_64:
libvorbis-1.3.6-2.el8.i686.rpm
libvorbis-1.3.6-2.el8.x86_64.rpm
libvorbis-debuginfo-1.3.6-2.el8.i686.rpm
libvorbis-debuginfo-1.3.6-2.el8.x86_64.rpm
libvorbis-debugsource-1.3.6-2.el8.i686.rpm
libvorbis-debugsource-1.3.6-2.el8.x86_64.rpm

Red Hat CodeReady Linux Builder (v. 8):

aarch64:
libvorbis-debuginfo-1.3.6-2.el8.aarch64.rpm
libvorbis-debugsource-1.3.6-2.el8.aarch64.rpm
libvorbis-devel-1.3.6-2.el8.aarch64.rpm

noarch:
libvorbis-devel-docs-1.3.6-2.el8.noarch.rpm

ppc64le:
libvorbis-debuginfo-1.3.6-2.el8.ppc64le.rpm
libvorbis-debugsource-1.3.6-2.el8.ppc64le.rpm
libvorbis-devel-1.3.6-2.el8.ppc64le.rpm

s390x:
libvorbis-debuginfo-1.3.6-2.el8.s390x.rpm
libvorbis-debugsource-1.3.6-2.el8.s390x.rpm
libvorbis-devel-1.3.6-2.el8.s390x.rpm

x86_64:
libvorbis-debuginfo-1.3.6-2.el8.i686.rpm
libvorbis-debuginfo-1.3.6-2.el8.x86_64.rpm
libvorbis-debugsource-1.3.6-2.el8.i686.rpm
libvorbis-debugsource-1.3.6-2.el8.x86_64.rpm
libvorbis-devel-1.3.6-2.el8.i686.rpm
libvorbis-devel-1.3.6-2.el8.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-10392
https://access.redhat.com/security/cve/CVE-2018-10393
https://access.redhat.com/security/updates/classification/#low
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----Version: GnuPG v1

iQIVAwUBXcHzA9zjgjWX9erEAQhmWA//e3+oSd9StUsLKdKkQ4w60jQ/qWu5YSFp
3bL+48ZEHWvEo74QOEAu/R2v9d24acDsVaSS8H3jyfba8RQLcXsqaKqf6o43GwXi
GwjchXv1pWb82agZ8FXa2Ny169vbQb+0wrTe9w1sOY7DaczSVMkTKdaVe9j3r1tm
HfHXo7+yQQL8bZYPnVVhMv0fKDpUzG/8Cg7O3x6+B83RcQ5V+6C1uBZX0/8X4eX1
VTZbf2+QGMTb1GoJOA2NH5cEMi1mGzcUHEV9HLvOXD/qAhsGa2ww3Oz8wKTFfOsg
zapOXI3atUOfJRNGc1raKriTdA3L1wXSW41rDMPIi+1rVJnRK2y6iSOlv60CszM2
Nhm+p8OSKT3VqSjmnjbC0euxxtOknFm3V/3VFu2EhAm/4sBttQQ4MjTe7tRh50P8
T3aJh7VMozJPSTgwHmqOAPf0lOVY4TcFpnMUjH/CoWhdjuGvz4eK8XKJnsFxqKi7
SLyhxdCjb83btDpK9UudBPHaD4XAlyf1xuwo45atYDMD9FRQ6afQxaI5Jse2ZbCG
jln8cxlkKx3p++LUycG3uiF9lhZtBKJLD0bLlCZut43pilcIyXbpqB+XyUxWRXQB
Fwmhys8dwMO8GdbTXsap7Vr2dh5aTG1qwX7JZtNBDi98RgLMURO/7dnKDy756/jZ
73oTAiCrCr4=zJip
-----END PGP SIGNATURE-------RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2019-3703:01 Low: libvorbis security update

An update for libvorbis is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low

Summary

The libvorbis package contains runtime libraries for use in programs that support Ogg Vorbis, a fully open, non-proprietary, patent- and royalty-free, general-purpose compressed format for audio and music at fixed and variable bitrates.
Security Fix(es):
* libvorbis: heap buffer overflow in mapping0_forward function (CVE-2018-10392)
* libvorbis: stack buffer overflow in bark_noise_hybridmp function (CVE-2018-10393)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2018-10392 https://access.redhat.com/security/cve/CVE-2018-10393 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: libvorbis-1.3.6-2.el8.src.rpm
aarch64: libvorbis-1.3.6-2.el8.aarch64.rpm libvorbis-debuginfo-1.3.6-2.el8.aarch64.rpm libvorbis-debugsource-1.3.6-2.el8.aarch64.rpm
ppc64le: libvorbis-1.3.6-2.el8.ppc64le.rpm libvorbis-debuginfo-1.3.6-2.el8.ppc64le.rpm libvorbis-debugsource-1.3.6-2.el8.ppc64le.rpm
s390x: libvorbis-1.3.6-2.el8.s390x.rpm libvorbis-debuginfo-1.3.6-2.el8.s390x.rpm libvorbis-debugsource-1.3.6-2.el8.s390x.rpm
x86_64: libvorbis-1.3.6-2.el8.i686.rpm libvorbis-1.3.6-2.el8.x86_64.rpm libvorbis-debuginfo-1.3.6-2.el8.i686.rpm libvorbis-debuginfo-1.3.6-2.el8.x86_64.rpm libvorbis-debugsource-1.3.6-2.el8.i686.rpm libvorbis-debugsource-1.3.6-2.el8.x86_64.rpm
Red Hat CodeReady Linux Builder (v. 8):
aarch64: libvorbis-debuginfo-1.3.6-2.el8.aarch64.rpm libvorbis-debugsource-1.3.6-2.el8.aarch64.rpm libvorbis-devel-1.3.6-2.el8.aarch64.rpm
noarch: libvorbis-devel-docs-1.3.6-2.el8.noarch.rpm
ppc64le: libvorbis-debuginfo-1.3.6-2.el8.ppc64le.rpm libvorbis-debugsource-1.3.6-2.el8.ppc64le.rpm libvorbis-devel-1.3.6-2.el8.ppc64le.rpm
s390x: libvorbis-debuginfo-1.3.6-2.el8.s390x.rpm libvorbis-debugsource-1.3.6-2.el8.s390x.rpm libvorbis-devel-1.3.6-2.el8.s390x.rpm
x86_64: libvorbis-debuginfo-1.3.6-2.el8.i686.rpm libvorbis-debuginfo-1.3.6-2.el8.x86_64.rpm libvorbis-debugsource-1.3.6-2.el8.i686.rpm libvorbis-debugsource-1.3.6-2.el8.x86_64.rpm libvorbis-devel-1.3.6-2.el8.i686.rpm libvorbis-devel-1.3.6-2.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2019:3703-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2019:3703
Issued Date: : 2019-11-05
CVE Names: CVE-2018-10392 CVE-2018-10393

Topic

An update for libvorbis is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat CodeReady Linux Builder (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64


Bugs Fixed

1574193 - CVE-2018-10392 libvorbis: heap buffer overflow in mapping0_forward function

1574194 - CVE-2018-10393 libvorbis: stack buffer overflow in bark_noise_hybridmp function


Related News