[FEDORA-2019-2e385f97e2] Fedora 29: mingw-libvorbis

Severity Critical
Affected Packages 1
CVEs 8

MinGW cross compiled libvorbis 1.3.6 + various patches backported from git.
This is a security fix for: CVE-2017-11333 CVE-2017-11735 CVE-2017-14160
CVE-2017-14632 CVE-2017-14633 CVE-2018-5146 CVE-2018-10392 CVE-2018-10393

Package Affected Version
pkg:rpm/fedora/mingw-libvorbis?distro=fedora-29 < 1.3.6.2.fc29
Source # ID Name URL
Bugzilla 1557221 Bug #1557221 - CVE-2018-5146 Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) https://bugzilla.redhat.com/show_bug.cgi?id=1557221
Bugzilla 1480645 Bug #1480645 - CVE-2017-11735 libvorbis: NULL pointer dereference in vorbis_block_clear function in lib/block.c https://bugzilla.redhat.com/show_bug.cgi?id=1480645
Bugzilla 1574193 Bug #1574193 - CVE-2018-10392 libvorbis: heap buffer overflow in mapping0_forward function https://bugzilla.redhat.com/show_bug.cgi?id=1574193
Bugzilla 1480643 Bug #1480643 - CVE-2017-11333 libvorbis: Memory exhaustion in vorbis_analysis_wrote function in lib/block.c https://bugzilla.redhat.com/show_bug.cgi?id=1480643
Bugzilla 1574194 Bug #1574194 - CVE-2018-10393 libvorbis: stack buffer overflow in bark_noise_hybridmp function https://bugzilla.redhat.com/show_bug.cgi?id=1574194
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/mingw-libvorbis?distro=fedora-29 fedora mingw-libvorbis < 1.3.6.2.fc29 fedora-29
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...