MGASA-2020-0193

Source
https://advisories.mageia.org/MGASA-2020-0193.html
Import Source
https://advisories.mageia.org/MGASA-2020-0193.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0193
Related
Published
2020-05-05T12:20:37Z
Modified
2024-02-14T18:04:42Z
Summary
Updated dolphin-emu packages fix security vulnerability
Details

Updated dolphin-emu package fixes security vulnerabilities

Dolphin Emulator includes a modified copy of the SoundTouch library at version 1.9.2. That version is subject to the following security issues:

  • The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file (CVE-2017-9258)

  • The TDStretch::acceptNewOverlapLength function in source/SoundTouch/ TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted wav file (CVE-2017-9259).

  • The TDStretchSSE::calcCrossCorr function in source/SoundTouch/ sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file (CVE-2017-9260).

  • Reachable assertion in RateTransposer::setChannels() causing denial of service (CVE-2018-14044).

  • Reachable assertion in FIRFilter.cpp causing denial of service (CVE-2018-14045).

  • Assertion failure in BPMDetect class in BPMDetect.cpp (CVE-2018-17096).

  • Out-of-bounds heap write in WavOutFile::write() (CVE-2018-17097).

  • Heap corruption in WavFileBase class in WavFile.cpp (CVE-2018-17098).

  • Heap-based buffer overflow in SoundStretch/WavFile.cpp:WavInFile ::readHeaderBlock() potentially leading to code execution (CVE-2018-1000223).

The bundled copy of SoundTouch was updated to version 2.1.2, thereby solving theses issues in Dolphin Emulator.

References
Credits

Affected packages

Mageia:7 / dolphin-emu

Package

Name
dolphin-emu
Purl
pkg:rpm/mageia/dolphin-emu?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.11824-1.mga7.tainted

Ecosystem specific

{
    "section": "tainted"
}