FS#70063 - [flac] [Security] information disclosure (CVE-2020-0499)
Attached to Project:
Arch Linux
Opened by Jonas Witschel (diabonas) - Thursday, 18 March 2021, 12:30 GMT
Last edited by Antonio Rojas (arojas) - Saturday, 08 May 2021, 18:37 GMT
Opened by Jonas Witschel (diabonas) - Thursday, 18 March 2021, 12:30 GMT
Last edited by Antonio Rojas (arojas) - Saturday, 08 May 2021, 18:37 GMT
|
Details
Summary
======= The package flac is vulnerable to information disclosure via CVE-2020-0499. Guidance ======== Applying commit 2e7931c27eb15e387da440a37f12437e35b22dd4 referenced below fixes the issue. References ========== https://security.archlinux.org/AVG-1376 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=17069 https://github.com/xiph/flac/commit/2e7931c27eb15e387da440a37f12437e35b22dd4 |
This task depends upon
Closed by Antonio Rojas (arojas)
Saturday, 08 May 2021, 18:37 GMT
Reason for closing: Fixed
Additional comments about closing: flac 1.3.3-3
Saturday, 08 May 2021, 18:37 GMT
Reason for closing: Fixed
Additional comments about closing: flac 1.3.3-3
Comment by
T.J. Townsend (blakkheim) -
Saturday, 08 May 2021, 17:46 GMT
Attached diff for the PKGBUILD adds that fix and another one to
"add some overflow checks for residual bits calculation."