MGASA-2023-0347

Source
https://advisories.mageia.org/MGASA-2023-0347.html
Import Source
https://advisories.mageia.org/MGASA-2023-0347.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0347
Related
Published
2023-12-15T17:57:51Z
Modified
2023-12-15T16:27:54Z
Summary
Updated audiofile packages fix a security vulnerability
Details

2 patches are added to audiofile source to correct a vulnerability. In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file. (CVE-2019-13147)

References
Credits

Affected packages

Mageia:9 / audiofile

Package

Name
audiofile
Purl
pkg:rpm/mageia/audiofile?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.6-14.mga9

Ecosystem specific

{
    "section": "core"
}