|
|
Log in / Subscribe / Register

Debian alert DLA-2697-1 (fluidsynth)

From:  Thorsten Alteholz <debian@alteholz.de>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2697-1] fluidsynth security update
Date:  Tue, 29 Jun 2021 21:48:00 +0000
Message-ID:  <alpine.DEB.2.21.2106292147040.21420@postfach.intern.alteholz.me>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2697-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Thorsten Alteholz June 29, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : fluidsynth Version : 1.1.6-4+deb9u1 CVE ID : CVE-2021-28421 A vulnerbility has been found in fluidsynth, a real-time MIDI software synthesizer. Using a special crafted soundfont2 file, a use after free vulnerability might result in arbitrary code execution or a denial of service (DoS). For Debian 9 stretch, this problem has been fixed in version 1.1.6-4+deb9u1. We recommend that you upgrade your fluidsynth packages. For the detailed security status of fluidsynth please refer to its security tracker page at: https://security-tracker.debian.org/tracker/fluidsynth Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmDblRBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7 WEeDOQ//d/3JJh8rxvHZ2iUcmBoANeMB2HviyeU9hz/VgsWr5x6JcTK3APyAc42+ UvX570fr9A9z15Ay3/ZJnEDqi+E6t98sEsMkQKLWcz+KGWWGq711m0WIa3ZncvuY jodfB0GcWfKGBQjCbt6MdhSWThQ3gf7X2KkVy27+5H8vffbJrXuSZzyNg8aNWXmu lrAdO2MzKi9jglFbtRNr0sHEHXQAW9p5Ny6ltPD4d9qM4uGd7IvEYOWKceTUW8BY ii9yje1CGgsxAdOcz06VDc8g4eZzn6Yu7+gA4IlGsZ9tjxitHTW8Dj8zEjPzQVqn hr5fVsM9+x2dh0fqzzXS89/oQjdo5+kfCDOmTi53fyZZ1YKCi7Be1Cd7ZWOvCEi6 AKkaYAKx/giYvxwtNXgVH3QfxrJnd/VYMFjD9lU3jj7d+E99G9zZAxZdypHYIZpz Lo/VBdyFJm0xTy2GtuxXIockI6vw/g/lsJsFYujJws3mZd9h/KOeS9iBYt2WNl5P BFkBIGjuWFT0MGt0iuDmf24TsAPKn8seX0dVOqFtsD6hlDceeM4jAv2b1eo/iGly P3Ef32ol/AGJ2jVqT9HiD4QEENE2rnW4hLOVTMgfh+s77LEYXCZaC5GrDuZARxm4 9gx4WFb8esTTXnG51CmTAlQWQ+PqZ1dyourYZEhq/CLQqdqkb3A= =ccVm -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds