speex-1.2.0-11.el9

エラータID: AXSA:2022-4570:01

Release date: 
Wednesday, December 28, 2022 - 01:43
Subject: 
speex-1.2.0-11.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Low
Description: 

Speex is a patent-free compression format designed especially for speech. It is specialized for voice communications at low bit-rates.

Security Fix(es):

* speex: divide by zero in read_samples() via crafted WAV file (CVE-2020-23903)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9.1 Release Notes linked from the References section.

CVE-2020-23903
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. speex-1.2.0-11.el9.src.rpm
    MD5: 18d1d1b238fe4cd4c28cfdc4031e0e28
    SHA-256: 632f808fba26a72d8fa8b7dba00fff255823508377ae004d44ebea3d7a5740cf
    Size: 1.01 MB

Asianux Server 9 for x86_64
  1. speex-1.2.0-11.el9.x86_64.rpm
    MD5: 7d8129b0917299346b8458e7ecfc1324
    SHA-256: 7b92d2e152449d6914e388285d9ccb0f4735866d3c42105cca03bd524839fc49
    Size: 66.50 kB
  2. speex-devel-1.2.0-11.el9.x86_64.rpm
    MD5: b1e54da404c3cc34de4a8cd9272eb009
    SHA-256: 2b71ed0980737e2f94a7fad38203fbe4d711cb1a61543606b5359f8c1cc3d08f
    Size: 418.37 kB
  3. speex-1.2.0-11.el9.i686.rpm
    MD5: b09992c6b8404a06f00503f2c361fa9f
    SHA-256: 2b6c52dc45ebab3bcdca9f1fd66517dbb09a3dcd44bc5f25b26eae82033fc1ff
    Size: 67.87 kB
  4. speex-devel-1.2.0-11.el9.i686.rpm
    MD5: d4785600dd077c400d17e2107ba04dbf
    SHA-256: 7d2eb8d4206e1d53a4b37e19d4c15cca6ae6cf71e53e02bb11b37a2b6b23e770
    Size: 418.34 kB