drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in audiofile
Name: |
Zwei Probleme in audiofile |
|
ID: |
USN-3800-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 14.04 LTS |
|
Datum: |
Mi, 24. Oktober 2018, 18:55 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13440
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17095 |
|
Applikationen: |
Audio File Library |
|
Originalnachricht |
--===============0953703988051492223== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="=-zu+7VfGwKJO0Bhi8UI7c"
--=-zu+7VfGwKJO0Bhi8UI7c Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-3800-1 October 24, 2018
audiofile vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in audiofile.
Software Description: - audiofile: Open-source version of the SGI audiofile library
Details:
It was discovered that audiofile incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-13440)
It was discovered that audiofile incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-17095)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.04 LTS: audiofile-tools 0.3.6-2ubuntu0.14.04.3 libaudiofile1 0.3.6-2ubuntu0.14.04.3
In general, a standard system update will make all the necessary changes.
References: https://usn.ubuntu.com/usn/usn-3800-1 CVE-2018-13440, CVE-2018-17095
Package Information: https://launchpad.net/ubuntu/+source/audiofile/0.3.6-2ubuntu0.14.04.3 --=-zu+7VfGwKJO0Bhi8UI7c Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAABCAAGBQJb0JMVAAoJEEW851uECx9pALYQAJFr4tE4NGoayn/51XuEzHMX bTS4xjJtwo+Yi6yU5tUZ8P5cCQ04aUhu5VgCQO7vXVd6m56qLgJfok1+ZkzubcI8 uYTt6PMBaZvoM1Dc9qPrI8yjjXo4JaHCHgMKNk98eHoe6uwbu/UBhRfB+OJtexpP x77Ae0IjV9S450APRhnWX3uYjmbjfPR2Uk5cSo7YTDG4ncL9xSBPOqbNQoCxPJsU iipSav08ZulnCYa704S2wj8u/voARzSnQHGnuLJ5ekDMDhDpsFdn6iMwlEUs51YL PpfTN2/RPSFkdvDq1OAge93E2pOXs2Vyf6E3b4Sa796x937On7IC8dG71oxSARPr k4KfaipfwX30dmSaqycdTEJ32V0JwSB51oor552bOJvkb3CGvciu1gAOJAklPO3u GE+ko1gta86nZ/eEXgyqrT9nhSxkd3ZV+P9MPX1ubvLFAHYzfrQYsT9ZAKIRdWWw PZpRx1tXvCSXPzeWFN4KCuoLb/Gtfve0xugRImv6FUYkggKJ13u+mcAkPn5zI8ag 9S8Df5T5X329gkJoujgqEaihNspb8IH+O2VuTFt1fiAkgokyw8/XkWJMGs8fkiU8 565WnU3+S4vf/RYFtY28RwragfV0+EBnEhNPVVowCCQ+bSxL4DrsEngVCqLV90CS XRe93syAXJ0axhDIYMeR =10Xl -----END PGP SIGNATURE-----
--=-zu+7VfGwKJO0Bhi8UI7c--
--===============0953703988051492223== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK
--===============0953703988051492223==--
|
|
|
|