Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in WavPack
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in WavPack
ID: USN-4682-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Mi, 6. Januar 2021, 23:47
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35738
Applikationen: WavPack

Originalnachricht


--===============4413751526042631610==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="x+6KMIRAuhnl3hBn"
Content-Disposition: inline


--x+6KMIRAuhnl3hBn
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-4682-1
January 06, 2021

wavpack vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

WavPack could be made to execute arbitrary code or crash if it received a
specially
crafted WAV file.

Software Description:
- wavpack: audio codec (lossy and lossless) - encoder and decoder

Details:

It was discovered that WavPack incorrectly handled certain WAV files.
An attacker could possibly use this issue to execute arbitrary code or
cause a crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
wavpack 5.3.0-1ubuntu0.1

Ubuntu 20.04 LTS:
wavpack 5.2.0-1ubuntu0.1

Ubuntu 18.04 LTS:
wavpack 5.1.0-2ubuntu1.5

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4682-1
CVE-2020-35738

Package Information:
https://launchpad.net/ubuntu/+source/wavpack/5.3.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/wavpack/5.2.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/wavpack/5.1.0-2ubuntu1.5

--x+6KMIRAuhnl3hBn
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl/1xYIACgkQRbznW4QL
H2l2gw//WjFPzZehC0k0siYPc6jseIbHJCq26DBF/irfilvendP4NEYYosaQbVu9
sSnPNRkWm0QKR9Qln/5F+fwATT12kEHUS81aIR1vZSe8g+9+d+cJDhOSwR9xB8cs
9H212oRFWgQyTNiRgl+nkNjLLU4whsfSmX1dHJfCe2CvQScMvVYo597qYrQcXzxJ
EsrPNWh/uJPRxibroBEshFMugPo0AlVi9VeCBovaDV066ZvBTaw4XEFFhz1vtE4f
qdUdSRsW9rJUlz1WVkqV8K/rtpzRMeyx+CyqCx3GcuxEvVGd1+QYtWpBWaUVXy/M
xFREXMote5QHFAfHSzmGU/9LynXcoqv6kNm0j4IbjZrBHJOEyGbzvQus+p6O0q1o
zDm/joA4S2hDmWWnHv5IzpDIW41GUrHBWocvDSuyZQvck07zxJm9Yd2D/ZpWn+dd
ltlp7flwoh3s/mFu3c/srCAvbVmMh0ek6UXFenjjJwPjqgMkZerWr0B3I4Xz+nrc
PNY6KqxZtRHnR3Oy0YDh0heMb9ypQWkldy+Zp74dGGvljPVtrl0obAIAIZFvtWWg
rDlW5bT+ivpAVbhj+srSLeuict2dpcqTI0cT9mboc2TKK0zgTsqN4bOiSUmIVJUd
S4Z1E7a+YhJStQHNZGG+hdu/0aRoXg7LEKmbTJKIjARyNNnCE+c=
=B6UK
-----END PGP SIGNATURE-----

--x+6KMIRAuhnl3hBn--


--===============4413751526042631610==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung