openSUSE Security Update: Security update for libsndfile ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:1427-1 Rating: moderate References: #1033054 #1033914 #1033915 #1036943 #1036944 #1036945 #1036946 #1038856 Cross-References: CVE-2017-7585 CVE-2017-7741 CVE-2017-7742 CVE-2017-8361 CVE-2017-8362 CVE-2017-8363 CVE-2017-8365 Affected Products: openSUSE Leap 42.2 ______________________________________________________________________________ An update that solves 7 vulnerabilities and has one errata is now available. Description: This update for libsndfile fixes the following issues: - CVE-2017-8361: Global buffer overflow in flac_buffer_copy. (bsc#1036946) - CVE-2017-8362: Invalid memory read in flac_buffer_copy. (bsc#1036943) - CVE-2017-8363: Heap-based buffer overflow in flac_buffer_copy. (bsc#1036945) - CVE-2017-7585, CVE-2017-7741, CVE-2017-7742: Stack-based buffer overflows via specially crafted FLAC files. (bsc#1033054) This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-625=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (i586 x86_64): libsndfile-debugsource-1.0.25-26.6.1 libsndfile-devel-1.0.25-26.6.1 libsndfile-progs-1.0.25-26.6.1 libsndfile-progs-debuginfo-1.0.25-26.6.1 libsndfile-progs-debugsource-1.0.25-26.6.1 libsndfile1-1.0.25-26.6.1 libsndfile1-debuginfo-1.0.25-26.6.1 - openSUSE Leap 42.2 (x86_64): libsndfile1-32bit-1.0.25-26.6.1 libsndfile1-debuginfo-32bit-1.0.25-26.6.1 References: https://www.suse.com/security/cve/CVE-2017-7585.html https://www.suse.com/security/cve/CVE-2017-7741.html https://www.suse.com/security/cve/CVE-2017-7742.html https://www.suse.com/security/cve/CVE-2017-8361.html https://www.suse.com/security/cve/CVE-2017-8362.html https://www.suse.com/security/cve/CVE-2017-8363.html https://www.suse.com/security/cve/CVE-2017-8365.html https://bugzilla.suse.com/1033054 https://bugzilla.suse.com/1033914 https://bugzilla.suse.com/1033915 https://bugzilla.suse.com/1036943 https://bugzilla.suse.com/1036944 https://bugzilla.suse.com/1036945 https://bugzilla.suse.com/1036946 https://bugzilla.suse.com/1038856