Bug ID 1185777
Summary VUL-0: CVE-2021-21417: fluidsynth: A use after free via invalid SoundFont file
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/283194/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee tiwai@suse.com
Reporter gianluca.gabrielli@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2021-21417

fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A
use after free violation was discovered in fluidsynth, that can be triggered
when loading an invalid SoundFont file.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1955611
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-21417
https://github.com/FluidSynth/fluidsynth/issues/808
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21417
https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-6fcq-pxhc-jxc9


You are receiving this mail because: