Bug 911796 - (CVE-2014-9496) VUL-0: CVE-2014-9496: libsndfile: two buffer read overflows in sd2_parse_rsrc_fork()
(CVE-2014-9496)
VUL-0: CVE-2014-9496: libsndfile: two buffer read overflows in sd2_parse_rs...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P2 - High : Major
: ---
Assigned To: Herbert Li
Security Team bot
https://smash.suse.de/issue/112012/
maint:released:sle11-sp1:60174 maint:...
: DSLA_REQUIRED, DSLA_SOLUTION_PROVIDED
Depends on:
Blocks: 969204
  Show dependency treegraph
 
Reported: 2015-01-06 09:26 UTC by Victor Pereira
Modified: 2016-04-08 11:56 UTC (History)
11 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
nli: needinfo? (zhen.xiao)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-01-06 09:26:35 UTC
UBUNTU:CVE-2014-9496

two potential buffer read overflows were found in libsndfile. 

References:
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9496.html
https://github.com/erikd/libsndfile/commit/dbe14f00030af5d3577f4cabbf98 (fix)
Comment 1 Swamp Workflow Management 2015-01-06 23:00:13 UTC
bugbot adjusting priority
Comment 3 Bernhard Wiedemann 2015-01-07 11:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (911796) was mentioned in
https://build.opensuse.org/request/show/280134 13.2 / libsndfile
https://build.opensuse.org/request/show/280135 13.1 / libsndfile
Comment 4 Swamp Workflow Management 2015-01-09 10:36:50 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-01-23.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/60173
Comment 5 Swamp Workflow Management 2015-01-14 14:06:05 UTC
openSUSE-SU-2015:0041-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 911796
CVE References: CVE-2014-9496
Sources used:
openSUSE 13.2 (src):    libsndfile-1.0.25-19.4.1, libsndfile-progs-1.0.25-19.4.1
openSUSE 13.1 (src):    libsndfile-1.0.25-17.4.1, libsndfile-progs-1.0.25-17.4.1
Comment 6 Takashi Iwai 2015-01-20 15:20:17 UTC
The fixes have been submitted to all branches.
Comment 7 Takashi Iwai 2015-01-20 15:21:51 UTC
Reassign to security team for the releases.
Comment 8 Swamp Workflow Management 2015-01-28 17:05:24 UTC
SUSE-SU-2015:0160-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 911796
CVE References: CVE-2014-9496
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    libsndfile-1.0.25-21.1
SUSE Linux Enterprise Server 12 (src):    libsndfile-1.0.25-21.1
SUSE Linux Enterprise Desktop 12 (src):    libsndfile-1.0.25-21.1
Comment 9 Swamp Workflow Management 2015-01-29 02:07:46 UTC
SUSE-SU-2015:0169-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 911796
CVE References: CVE-2014-9496
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    libsndfile-1.0.20-2.6.5
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    libsndfile-1.0.20-2.6.5
SUSE Linux Enterprise Server 11 SP3 (src):    libsndfile-1.0.20-2.6.5
SUSE Linux Enterprise Desktop 11 SP3 (src):    libsndfile-1.0.20-2.6.5
Comment 10 Johannes Segitz 2015-03-25 14:27:44 UTC
all updates released
Comment 21 Tristan Ye 2016-02-05 06:58:15 UTC
Guys, have we fixed this issue against SLES 11SP1?