LWN.net Logo

Scientific Linux alert SL-libs-20110720 (libsndfile)

From:  "Tyler L. Parsons" <tparsons@fnal.gov>
To:  "scientific-linux-errata@fnal.gov" <scientific-linux-errata@fnal.gov>
Subject:  Security ERRATA Moderate: libsndfile on SL6.x i386/x86_64
Date:  Fri, 22 Jul 2011 09:51:49 -0500
Message-ID:  <038136A29FA425469182B3C95D7E54210102739CC979@MAPI1.fnal.gov>
Archive-link:  Article, Thread

Synopsis: Moderate: libsndfile security update Issue Date: 2011-07-20 CVE Numbers: CVE-2011-2696 The libsndfile packages provide a library for reading and writing sound files. An integer overflow flaw, leading to a heap-based buffer overflow, was found in the way the libsndfile library processed certain Ensoniq PARIS Audio Format (PAF) audio files. An attacker could create a specially-crafted PAF file that, when opened, could cause an application using libsndfile to crash or, potentially, execute arbitrary code with the privileges of the user running the application. (CVE-2011-2696) Users of libsndfile are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. All running applications using libsndfile must be restarted for the update to take effect. SL6: i386 libsndfile-1.0.20-3.el6_1.1.i686.rpm libsndfile-debuginfo-1.0.20-3.el6_1.1.i686.rpm libsndfile-devel-1.0.20-3.el6_1.1.i686.rpm x86_64 libsndfile-1.0.20-3.el6_1.1.i686.rpm libsndfile-1.0.20-3.el6_1.1.x86_64.rpm libsndfile-debuginfo-1.0.20-3.el6_1.1.i686.rpm libsndfile-debuginfo-1.0.20-3.el6_1.1.x86_64.rpm libsndfile-devel-1.0.20-3.el6_1.1.i686.rpm libsndfile-devel-1.0.20-3.el6_1.1.x86_64.rpm - Scientific Linux Development Team


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds