Bugzilla – Bug 1033915
VUL-0: CVE-2017-7741: libsndfile: versions before 1.0.28 have write memory access issue on function flac_buffer_copy()
Last modified: 2018-10-04 22:45:32 UTC
CVE-2017-7741 In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7741 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-7741.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7741 http://www.cvedetails.com/cve/CVE-2017-7741/ https://blogs.gentoo.org/ago/2017/04/11/libsndfile-invalid-memory-read-and-invalid-memory-write-in/
I suppose the fix is identical with CVE-2017-7585? Do I need to resubmit with the updated changelog?
is it the same fix?
NVD points to the same commit ID as the fix. https://github.com/erikd/libsndfile/commit/60b234301adf258786d8b90be5c1d437fc8799e0 And I noticed that bsc#1033054 already mentions three CVE's.
SUSE-SU-2017:1030-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1033054,1033914,1033915 CVE References: CVE-2017-7585,CVE-2017-7741,CVE-2017-7742 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): libsndfile-1.0.20-2.13.1 SUSE Linux Enterprise Server 11-SP4 (src): libsndfile-1.0.20-2.13.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): libsndfile-1.0.20-2.13.1
SUSE-SU-2017:1040-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1033053,1033054,1033914,1033915 CVE References: CVE-2017-7585,CVE-2017-7586,CVE-2017-7741,CVE-2017-7742 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP2 (src): libsndfile-1.0.25-28.1 SUSE Linux Enterprise Software Development Kit 12-SP1 (src): libsndfile-1.0.25-28.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): libsndfile-1.0.25-28.1 SUSE Linux Enterprise Server 12-SP2 (src): libsndfile-1.0.25-28.1 SUSE Linux Enterprise Server 12-SP1 (src): libsndfile-1.0.25-28.1 SUSE Linux Enterprise Desktop 12-SP2 (src): libsndfile-1.0.25-28.1 SUSE Linux Enterprise Desktop 12-SP1 (src): libsndfile-1.0.25-28.1
The fix was submitted to both SLE11 and SLE12. Reassigned back to security team.
released. changes diff queued for potential next update
openSUSE-SU-2017:1107-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1033053,1033054,1033914,1033915 CVE References: CVE-2017-7585,CVE-2017-7586,CVE-2017-7741,CVE-2017-7742 Sources used: openSUSE Leap 42.2 (src): libsndfile-1.0.25-26.3.1, libsndfile-progs-1.0.25-26.3.1 openSUSE Leap 42.1 (src): libsndfile-1.0.25-27.1, libsndfile-progs-1.0.25-27.1
SUSE-SU-2017:1236-1: An update that fixes 7 vulnerabilities is now available. Category: security (moderate) Bug References: 1033054,1033914,1033915,1036943,1036944,1036945,1036946 CVE References: CVE-2017-7585,CVE-2017-7741,CVE-2017-7742,CVE-2017-8361,CVE-2017-8362,CVE-2017-8363,CVE-2017-8365 Sources used: SUSE Linux Enterprise Software Development Kit 11-SP4 (src): libsndfile-1.0.20-2.18.1 SUSE Linux Enterprise Server 11-SP4 (src): libsndfile-1.0.20-2.18.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): libsndfile-1.0.20-2.18.1
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2017-05-31. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/63616
SUSE-SU-2017:1367-1: An update that solves 7 vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1033054,1033914,1033915,1036943,1036944,1036945,1036946,1038856 CVE References: CVE-2017-7585,CVE-2017-7741,CVE-2017-7742,CVE-2017-8361,CVE-2017-8362,CVE-2017-8363,CVE-2017-8365 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP2 (src): libsndfile-1.0.25-35.1 SUSE Linux Enterprise Software Development Kit 12-SP1 (src): libsndfile-1.0.25-35.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): libsndfile-1.0.25-35.1 SUSE Linux Enterprise Server 12-SP2 (src): libsndfile-1.0.25-35.1 SUSE Linux Enterprise Server 12-SP1 (src): libsndfile-1.0.25-35.1 SUSE Linux Enterprise Desktop 12-SP2 (src): libsndfile-1.0.25-35.1 SUSE Linux Enterprise Desktop 12-SP1 (src): libsndfile-1.0.25-35.1
openSUSE-SU-2017:1427-1: An update that solves 7 vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1033054,1033914,1033915,1036943,1036944,1036945,1036946,1038856 CVE References: CVE-2017-7585,CVE-2017-7741,CVE-2017-7742,CVE-2017-8361,CVE-2017-8362,CVE-2017-8363,CVE-2017-8365 Sources used: openSUSE Leap 42.2 (src): libsndfile-1.0.25-26.6.1, libsndfile-progs-1.0.25-26.6.1
released