This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============2536237277921223849== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="9c84I7rACIIo4Xmtc3f6nlnJA5BqGdDUq"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --9c84I7rACIIo4Xmtc3f6nlnJA5BqGdDUq Content-Type: multipart/mixed; boundary="K1CrVNTHHNpVd9hAEXEmV6GPL5z5FYWpx"
--K1CrVNTHHNpVd9hAEXEmV6GPL5z5FYWpx Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable Content-Language: en-US
========================================================================== Ubuntu Security Notice USN-4704-1 January 26, 2021
libsndfile vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS - Ubuntu 14.04 ESM
Summary:
Several security issues were fixed in libsndfile.
Software Description: - libsndfile: Library for reading/writing audio files
Details:
It was discovered that libsndfile incorrectly handled certain malformed files. A remote attacker could use this issue to cause libsndfile to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2017-12562)
It was discovered that libsndfile incorrectly handled certain malformed files. A remote attacker could use this issue to cause libsndfile to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-14245, CVE-2017-14246, CVE-2017-14634, CVE-2017-16942, CVE-2017-6892, CVE-2018-13139, CVE-2018-19432, CVE-2018-19661, CVE-2018-19662, CVE-2018-19758, CVE-2019-3832)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04 LTS: libsndfile1 1.0.25-10ubuntu0.16.04.3 sndfile-programs 1.0.25-10ubuntu0.16.04.3
Ubuntu 14.04 ESM: libsndfile1 1.0.25-7ubuntu2.2+esm1 sndfile-programs 1.0.25-7ubuntu2.2+esm1
After a standard system update you need to restart your session to make all the necessary changes.
References: https://usn.ubuntu.com/4704-1 CVE-2017-12562, CVE-2017-14245, CVE-2017-14246, CVE-2017-14634, CVE-2017-16942, CVE-2017-6892, CVE-2018-13139, CVE-2018-19432, CVE-2018-19661, CVE-2018-19662, CVE-2018-19758, CVE-2019-3832
Package Information: https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3
--K1CrVNTHHNpVd9hAEXEmV6GPL5z5FYWpx--
--9c84I7rACIIo4Xmtc3f6nlnJA5BqGdDUq Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCAAdFiEElnO/d49FoUPK9fwytGdj0GOh2+wFAmAQRg8ACgkQtGdj0GOh 2+wghgf9FNDykhMOU6vpVQbC3MDp1FtaXMLxKJjvgVcKdHWlyp/+G4RbA7PiH8hz 2BoPsT9KyJQk55KiIHVoRsqigeWTNXtpV4YXqrK2yfj0ydPqjr+eR+gMu4BxE5Sc IFrHSOZZfypxkkyN0V9dW8HB3XFtcvL0f2ZFNLyhuvF7L7mYEwNIvm9SiSyn27PN rNZrV4jZpucoqc230UcA//yBCAeBf6Np8Ycuh+2Je+Sucy9qDJ3pqB5rZMAkaau2 qgRbzWL6Atu/t/mn9H6Ce89ZFfU4aaIpW+IO7xeHmHsTaFjRbIPrgS6B77tG0XsW WG1LHfvdfTP8tYhaitx1W+BhJlCPEw== =dFpK -----END PGP SIGNATURE-----
--9c84I7rACIIo4Xmtc3f6nlnJA5BqGdDUq--
--===============2536237277921223849== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK
--===============2536237277921223849==--
|