{
  "schema_version": "1.7.0",
  "id": "MGASA-2020-0476",
  "published": "2020-12-29T11:57:17Z",
  "modified": "2020-12-29T10:48:31Z",
  "summary": "Updated jackit packages fix security vulnerability",
  "details": "posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 has a \"double\nfile descriptor close\" issue during a failed connection attempt when jackd2 is\nnot running. Exploitation success depends on multithreaded timing of that\ndouble close, which can result in unintended information disclosure, crashes,\nor file corruption due to having the wrong file associated with the file\ndescriptor (CVE-2019-13351).\n",
  "upstream": [
    "CVE-2019-13351"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2020-0476.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=27775"
    },
    {
      "type": "ADVISORY",
      "url": "https://ubuntu.com/security/CVE-2019-13351"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "jackit",
        "purl": "pkg:rpm/mageia/jackit?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.9.12-2.1.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
