Bugzilla – Bug 911796
VUL-0: CVE-2014-9496: libsndfile: two buffer read overflows in sd2_parse_rsrc_fork()
Last modified: 2016-04-08 11:56:26 UTC
UBUNTU:CVE-2014-9496 two potential buffer read overflows were found in libsndfile. References: http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9496.html https://github.com/erikd/libsndfile/commit/dbe14f00030af5d3577f4cabbf98 (fix)
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (911796) was mentioned in https://build.opensuse.org/request/show/280134 13.2 / libsndfile https://build.opensuse.org/request/show/280135 13.1 / libsndfile
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2015-01-23. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/60173
openSUSE-SU-2015:0041-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 911796 CVE References: CVE-2014-9496 Sources used: openSUSE 13.2 (src): libsndfile-1.0.25-19.4.1, libsndfile-progs-1.0.25-19.4.1 openSUSE 13.1 (src): libsndfile-1.0.25-17.4.1, libsndfile-progs-1.0.25-17.4.1
The fixes have been submitted to all branches.
Reassign to security team for the releases.
SUSE-SU-2015:0160-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 911796 CVE References: CVE-2014-9496 Sources used: SUSE Linux Enterprise Software Development Kit 12 (src): libsndfile-1.0.25-21.1 SUSE Linux Enterprise Server 12 (src): libsndfile-1.0.25-21.1 SUSE Linux Enterprise Desktop 12 (src): libsndfile-1.0.25-21.1
SUSE-SU-2015:0169-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 911796 CVE References: CVE-2014-9496 Sources used: SUSE Linux Enterprise Software Development Kit 11 SP3 (src): libsndfile-1.0.20-2.6.5 SUSE Linux Enterprise Server 11 SP3 for VMware (src): libsndfile-1.0.20-2.6.5 SUSE Linux Enterprise Server 11 SP3 (src): libsndfile-1.0.20-2.6.5 SUSE Linux Enterprise Desktop 11 SP3 (src): libsndfile-1.0.20-2.6.5
all updates released
Guys, have we fixed this issue against SLES 11SP1?