audiofile-0.3.6-9.el7

エラータID: AXSA:2020-752:01

Release date: 
Friday, October 16, 2020 - 14:40
Subject: 
audiofile-0.3.6-9.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

An update for audiofile is now available for Asianux Server 7.

Asianux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

The Audio File library is an implementation of the Audio File Library from SGI, which provides an API for accessing audio file formats like AIFF/AIFF-C, WAVE, and NeXT/Sun .snd/.au files.

Security Fix(es):

* audiofile: Heap-based buffer overflow in Expand3To4Module::run() when running sfconvert (CVE-2018-17095)

* audiofile: NULL pointer dereference in ModuleState::setup() in modules/ModuleState.cpp allows for denial of service via crafted file (CVE-2018-13440)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 7 Release Notes linked from the References section.

CVE-2018-13440
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.
CVE-2018-17095
An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. audiofile-0.3.6-9.el7.src.rpm
    MD5: dc2aa4a6bf2ec95f834464e1635ebbdb
    SHA-256: d073c3af4c9d4836641ebc9feb12377c8e6ae6b9784a2400da2a56076174e204
    Size: 810.16 kB

Asianux Server 7 for x86_64
  1. audiofile-0.3.6-9.el7.x86_64.rpm
    MD5: 1a9fc1c1f200eebca4d20973e0ef0609
    SHA-256: 8e82efa112591085e04b1612c3d26aeed33f8e735db45b97d18ab77c91abf565
    Size: 153.20 kB
  2. audiofile-devel-0.3.6-9.el7.x86_64.rpm
    MD5: 528d1befe46b4782dee02a534a8b1e11
    SHA-256: 14f5983c365c2e8c2237c4d277f9934b1a522194fb15812e22cfe4176a5b0ade
    Size: 37.75 kB
  3. audiofile-0.3.6-9.el7.i686.rpm
    MD5: d70e0deb3d8f09ebf38c5ad6d75111a5
    SHA-256: 3fbf060eb201e82428028a985fea32204eab4b6037779ca7146b8f13332c8d78
    Size: 156.75 kB
  4. audiofile-devel-0.3.6-9.el7.i686.rpm
    MD5: aab67cd4385b73a65105140686909ca2
    SHA-256: 559feaba9a015eb7df15150ccd102caf0bad9e6e37e44241c78659e5b2b557bc
    Size: 37.79 kB