Oval Definition:oval:org.opensuse.security:def:69658
Revision Date:2021-01-21Version:1
Title:Security update for wavpack (Moderate)
Description:

This update for wavpack fixes the following issues:

- Update to version 5.4.0 * CVE-2020-35738: Fixed an out-of-bounds write in WavpackPackSamples (bsc#1180414) * fixed: disable A32 asm code when building for Apple silicon * fixed: issues with Adobe-style floating-point WAV files * added: --normalize-floats option to wvunpack for correctly exporting un-normalized floating-point files - Update to version 5.3.0 * fixed: OSS-Fuzz issues 19925, 19928, 20060, 20448 * fixed: trailing garbage characters on imported ID3v2 TXXX tags * fixed: various minor undefined behavior and memory access issues * fixed: sanitize tag extraction names for length and path inclusion * improved: reformat wvunpack 'help' and split into long + short versions * added: regression testing to Travis CI for OSS-Fuzz crashers - Updated to version 5.2.0 *fixed: potential security issues including the following CVEs: CVE-2018-19840, CVE-2018-19841, CVE-2018-10536 (bsc#1091344), CVE-2018-10537 (bsc#1091343) CVE-2018-10538 (bsc#1091342), CVE-2018-10539 (bsc#1091341), CVE-2018-10540 (bsc#1091340), CVE-2018-7254, CVE-2018-7253, CVE-2018-6767, CVE-2019-11498 and CVE-2019-1010319 * added: support for CMake, Travis CI, and Google's OSS-fuzz * fixed: use correction file for encode verify (pipe input, Windows) * fixed: correct WAV header with actual length (pipe input, -i option) * fixed: thumb interworking and not needing v6 architecture (ARM asm) * added: handle more ID3v2.3 tag items and from all file types * fixed: coredump on Sparc64 (changed MD5 implementation) * fixed: handle invalid ID3v2.3 tags from sacd-ripper * fixed: several corner-case memory leaks
Family:unixClass:patch
Status:Reference(s):1065729
1091340
1091341
1091342
1091343
1091344
1140683
1172538
1174748
1175520
1176400
1176946
1177027
1177340
1177511
1177685
1177724
1177725
1180414
CVE-2009-5044
CVE-2009-5080
CVE-2009-5081
CVE-2018-10536
CVE-2018-10537
CVE-2018-10538
CVE-2018-10539
CVE-2018-10540
CVE-2018-19840
CVE-2018-19841
CVE-2018-6767
CVE-2018-7253
CVE-2018-7254
CVE-2019-1010319
CVE-2019-11498
CVE-2020-12351
CVE-2020-12352
CVE-2020-25645
CVE-2020-35738
SUSE-SU-2020:2972-1
SUSE-SU-2021:0186-1
Platform(s):SUSE Linux Enterprise Module for Basesystem 15 SP2
SUSE Linux Enterprise Server 15 SP1-BCL
SUSE Linux Enterprise Workstation Extension 15 SP1
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP2 is installed
  • AND Package Information
  • groff-1.22.3-3 is installed
  • OR groff-full-1.22.3-3 is installed
  • OR gxditview-1.22.3-3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 15 SP1-BCL is installed
  • AND Package Information
  • libwavpack1-5.4.0-4.9.1 is installed
  • OR wavpack-5.4.0-4.9.1 is installed
  • OR wavpack-devel-5.4.0-4.9.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Workstation Extension 15 SP1 is installed
  • AND Package Information
  • kernel-default-4.12.14-197.64 is installed
  • OR kernel-default-extra-4.12.14-197.64 is installed
  • BACK