Ausführen beliebiger Kommandos in WavPack
ID: | USN-4682-1 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10 |
Datum: | Mi, 6. Januar 2021, 23:47 |
Referenzen: | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35738 |
Applikationen: | WavPack |
Originalnachricht |
|
--===============4413751526042631610== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="x+6KMIRAuhnl3hBn" Content-Disposition: inline --x+6KMIRAuhnl3hBn Content-Type: text/plain; charset=us-ascii Content-Disposition: inline ========================================================================== Ubuntu Security Notice USN-4682-1 January 06, 2021 wavpack vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: WavPack could be made to execute arbitrary code or crash if it received a specially crafted WAV file. Software Description: - wavpack: audio codec (lossy and lossless) - encoder and decoder Details: It was discovered that WavPack incorrectly handled certain WAV files. An attacker could possibly use this issue to execute arbitrary code or cause a crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: wavpack 5.3.0-1ubuntu0.1 Ubuntu 20.04 LTS: wavpack 5.2.0-1ubuntu0.1 Ubuntu 18.04 LTS: wavpack 5.1.0-2ubuntu1.5 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/4682-1 CVE-2020-35738 Package Information: https://launchpad.net/ubuntu/+source/wavpack/5.3.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/wavpack/5.2.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu1.5 --x+6KMIRAuhnl3hBn Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl/1xYIACgkQRbznW4QL H2l2gw//WjFPzZehC0k0siYPc6jseIbHJCq26DBF/irfilvendP4NEYYosaQbVu9 sSnPNRkWm0QKR9Qln/5F+fwATT12kEHUS81aIR1vZSe8g+9+d+cJDhOSwR9xB8cs 9H212oRFWgQyTNiRgl+nkNjLLU4whsfSmX1dHJfCe2CvQScMvVYo597qYrQcXzxJ EsrPNWh/uJPRxibroBEshFMugPo0AlVi9VeCBovaDV066ZvBTaw4XEFFhz1vtE4f qdUdSRsW9rJUlz1WVkqV8K/rtpzRMeyx+CyqCx3GcuxEvVGd1+QYtWpBWaUVXy/M xFREXMote5QHFAfHSzmGU/9LynXcoqv6kNm0j4IbjZrBHJOEyGbzvQus+p6O0q1o zDm/joA4S2hDmWWnHv5IzpDIW41GUrHBWocvDSuyZQvck07zxJm9Yd2D/ZpWn+dd ltlp7flwoh3s/mFu3c/srCAvbVmMh0ek6UXFenjjJwPjqgMkZerWr0B3I4Xz+nrc PNY6KqxZtRHnR3Oy0YDh0heMb9ypQWkldy+Zp74dGGvljPVtrl0obAIAIZFvtWWg rDlW5bT+ivpAVbhj+srSLeuict2dpcqTI0cT9mboc2TKK0zgTsqN4bOiSUmIVJUd S4Z1E7a+YhJStQHNZGG+hdu/0aRoXg7LEKmbTJKIjARyNNnCE+c= =B6UK -----END PGP SIGNATURE----- --x+6KMIRAuhnl3hBn-- --===============4413751526042631610== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce |