Advisories ยป MGASA-2019-0016

Updated aubio packages fix security vulnerabilities

Publication date: 06 Jan 2019
Modification date: 06 Jan 2019
Type: security
Affected Mageia releases : 6
CVE: CVE-2017-17554 , CVE-2018-14522 , CVE-2018-14523

Description

NULL pointer dereference in the function aubio_source_avcodec_readframe
which may lead to DoS when playing a crafted audio file (CVE-2017-17554).

A crash in aubio_pitch_set_unit (CVE-2018-14522).

A buffer overrread resulting in crash or information leakage in
new_aubio_pitchyinfft (CVE-2018-14523).
                

References

SRPMS

6/core