[ubuntu/impish-proposed] libsndfile 1.0.31-1ubuntu2 (Accepted)

Alex Murray alex.murray at canonical.com
Wed Jul 28 01:43:11 UTC 2021


libsndfile (1.0.31-1ubuntu2) impish; urgency=medium

  * SECURITY UPDATE: heap buffer overflow in msadpcm_decode_block allows
    arbitrary code execution via crafted WAV file.
    - debian/patches/CVE-2021-3246.patch: upstream patch to src/ms_adpcm.c
      to validate samples per block
    - CVE-2021-3246

Date: Mon, 26 Jul 2021 17:02:42 +0930
Changed-By: Alex Murray <alex.murray at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/libsndfile/1.0.31-1ubuntu2
-------------- next part --------------
Format: 1.8
Date: Mon, 26 Jul 2021 17:02:42 +0930
Source: libsndfile
Built-For-Profiles: noudeb
Architecture: source
Version: 1.0.31-1ubuntu2
Distribution: impish
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Alex Murray <alex.murray at canonical.com>
Changes:
 libsndfile (1.0.31-1ubuntu2) impish; urgency=medium
 .
   * SECURITY UPDATE: heap buffer overflow in msadpcm_decode_block allows
     arbitrary code execution via crafted WAV file.
     - debian/patches/CVE-2021-3246.patch: upstream patch to src/ms_adpcm.c
       to validate samples per block
     - CVE-2021-3246
Checksums-Sha1:
 8297bbcdadd92c4d81f390020041d6dcf848f347 2095 libsndfile_1.0.31-1ubuntu2.dsc
 0b6141180757a24977d674d363063bf6faad336f 14604 libsndfile_1.0.31-1ubuntu2.debian.tar.xz
 6556584960c3b7da5bdbe61e6025449300b49b9d 6996 libsndfile_1.0.31-1ubuntu2_source.buildinfo
Checksums-Sha256:
 48ef9036dd85170aab74e1c6da705527715854ceb3b27bee45d7680df2d69bfd 2095 libsndfile_1.0.31-1ubuntu2.dsc
 0481a939b5339b21d644d3043ea50bb14b157342ea0731f44709aaafebe21fad 14604 libsndfile_1.0.31-1ubuntu2.debian.tar.xz
 4aeca996f83ea6622b15de70f2eebe315e6252e69a736299fc607c854c23ad07 6996 libsndfile_1.0.31-1ubuntu2_source.buildinfo
Files:
 7b2f7e705bc17368f07ef7d017cbe3a7 2095 devel optional libsndfile_1.0.31-1ubuntu2.dsc
 09ae08b0cf74a2d5270a364cef833ba0 14604 devel optional libsndfile_1.0.31-1ubuntu2.debian.tar.xz
 cd7bac3d16152b4add31ac3f30572a23 6996 devel optional libsndfile_1.0.31-1ubuntu2_source.buildinfo
Original-Maintainer: Debian Multimedia Maintainers <debian-multimedia at lists.debian.org>


More information about the impish-changes mailing list