Oval Definition:oval:org.opensuse.security:def:66810
Revision Date:2021-01-21Version:1
Title:Security update for wavpack (Moderate)
Description:

This update for wavpack fixes the following issues:

- Update to version 5.4.0 * CVE-2020-35738: Fixed an out-of-bounds write in WavpackPackSamples (bsc#1180414) * fixed: disable A32 asm code when building for Apple silicon * fixed: issues with Adobe-style floating-point WAV files * added: --normalize-floats option to wvunpack for correctly exporting un-normalized floating-point files - Update to version 5.3.0 * fixed: OSS-Fuzz issues 19925, 19928, 20060, 20448 * fixed: trailing garbage characters on imported ID3v2 TXXX tags * fixed: various minor undefined behavior and memory access issues * fixed: sanitize tag extraction names for length and path inclusion * improved: reformat wvunpack 'help' and split into long + short versions * added: regression testing to Travis CI for OSS-Fuzz crashers - Updated to version 5.2.0 *fixed: potential security issues including the following CVEs: CVE-2018-19840, CVE-2018-19841, CVE-2018-10536 (bsc#1091344), CVE-2018-10537 (bsc#1091343) CVE-2018-10538 (bsc#1091342), CVE-2018-10539 (bsc#1091341), CVE-2018-10540 (bsc#1091340), CVE-2018-7254, CVE-2018-7253, CVE-2018-6767, CVE-2019-11498 and CVE-2019-1010319 * added: support for CMake, Travis CI, and Google's OSS-fuzz * fixed: use correction file for encode verify (pipe input, Windows) * fixed: correct WAV header with actual length (pipe input, -i option) * fixed: thumb interworking and not needing v6 architecture (ARM asm) * added: handle more ID3v2.3 tag items and from all file types * fixed: coredump on Sparc64 (changed MD5 implementation) * fixed: handle invalid ID3v2.3 tags from sacd-ripper * fixed: several corner-case memory leaks
Family:unixClass:patch
Status:Reference(s):1091340
1091341
1091342
1091343
1091344
1180414
CVE-2009-5155
CVE-2010-3192
CVE-2012-3406
CVE-2013-4458
CVE-2014-7817
CVE-2014-8121
CVE-2014-9402
CVE-2014-9761
CVE-2015-1472
CVE-2015-1473
CVE-2015-1781
CVE-2015-5180
CVE-2015-7547
CVE-2015-8325
CVE-2015-8776
CVE-2015-8777
CVE-2015-8778
CVE-2015-8779
CVE-2016-0777
CVE-2016-0778
CVE-2016-10009
CVE-2016-10010
CVE-2016-10011
CVE-2016-10012
CVE-2016-10739
CVE-2016-1234
CVE-2016-3075
CVE-2016-3706
CVE-2016-4429
CVE-2016-5417
CVE-2016-6210
CVE-2016-6323
CVE-2016-6515
CVE-2016-8858
CVE-2017-1000366
CVE-2017-1000408
CVE-2017-1000409
CVE-2017-12132
CVE-2017-12133
CVE-2017-15670
CVE-2017-15671
CVE-2017-15804
CVE-2017-16997
CVE-2017-17426
CVE-2017-18269
CVE-2018-1000001
CVE-2018-10536
CVE-2018-10537
CVE-2018-10538
CVE-2018-10539
CVE-2018-10540
CVE-2018-11236
CVE-2018-11237
CVE-2018-19840
CVE-2018-19841
CVE-2018-20685
CVE-2018-6485
CVE-2018-6551
CVE-2018-6767
CVE-2018-7253
CVE-2018-7254
CVE-2019-1010319
CVE-2019-11498
CVE-2019-19126
CVE-2019-6109
CVE-2019-6110
CVE-2019-6111
CVE-2019-9169
CVE-2020-10029
CVE-2020-1751
CVE-2020-1752
CVE-2020-35738
Platform(s):SUSE Linux Enterprise Module for Development Tools 15 SP2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Module for Server Applications 15 SP2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Development Tools 15 SP2 is installed
  • AND Package Information
  • glibc-devel-32bit-2.26-13.48 is installed
  • OR glibc-devel-static-2.26-13.48 is installed
  • OR glibc-utils-2.26-13.48 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Server Applications 15 SP2 is installed
  • AND openssh-fips-8.1p1-3 is installed
  • BACK