libcdio-0.92-3.el7

エラータID: AXSA:2018-3427:01

Release date: 
Friday, November 9, 2018 - 08:25
Subject: 
libcdio-0.92-3.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Low
Description: 

The libcdio library provides an interface for CD-ROM access. It can be used by applications that need OS-independent and device-independent access to CD-ROM devices.

Security Fix(es):

* libcdio: Heap-based buffer over-read in print_iso9660_recurse function in iso-info.c (CVE-2017-18198)

* libcdio: NULL pointer dereference in realloc_symlink in rock.c (CVE-2017-18199)

* libcdio: Double free in get_cdtext_generic() in lib/driver/_cdio_generic.c (CVE-2017-18201)

For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 7.6 Release Notes linked from the References section.

CVE-2017-18198
print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows
remote attackers to cause a denial of service (heap-based buffer
over-read) or possibly have unspecified other impact via a crafted iso
file.
CVE-2017-18199
realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote
attackers to cause a denial of service (NULL Pointer Dereference) via a
crafted iso file.
CVE-2017-18201
An issue was discovered in GNU libcdio before 2.0.0. There is a double
free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. libcdio-0.92-3.el7.src.rpm
    MD5: fda7376b4fa27833245bbc7cc3ae5464
    SHA-256: 1d22923f41571f818045bc9e5fd56f6749218d2be197b1d0f0968abe72973a64
    Size: 2.58 MB

Asianux Server 7 for x86_64
  1. libcdio-0.92-3.el7.x86_64.rpm
    MD5: 3fc04b09242be010284cea75f6bfd588
    SHA-256: 955b2d6007489942a1c4812b5e132d0fe3a30384ad81cab720d8e9f79d93559c
    Size: 235.04 kB
  2. libcdio-0.92-3.el7.i686.rpm
    MD5: 3fa057dc8a237952d3fae6e0715d3cba
    SHA-256: 615050f7a947f665cba9ef953601027aeb44cdb22b3822d25d1fd87c2f6d85b1
    Size: 235.36 kB