[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#905491: marked as done (soundtouch: CVE-2018-1000223: Heap-based buffer overflow in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock())



Your message dated Thu, 20 Dec 2018 22:37:53 +0000
with message-id <E1ga6wz-000Fz5-J1@fasolo.debian.org>
and subject line Bug#905491: fixed in soundtouch 2.1.2+ds1-1
has caused the Debian Bug report #905491,
regarding soundtouch: CVE-2018-1000223: Heap-based buffer overflow in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock()
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
905491: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=905491
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Source: soundtouch
Version: 1.9.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.com/soundtouch/soundtouch/issues/6

Hi,

The following vulnerability was published for soundtouch, filling the
bug to track the upstream issue.

CVE-2018-1000223[0]:
|Heap-based buffer overflow in
|SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() potentially
|leading to code execution

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-1000223
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000223
[1] https://gitlab.com/soundtouch/soundtouch/issues/6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: soundtouch
Source-Version: 2.1.2+ds1-1

We believe that the bug you reported is fixed in the latest version of
soundtouch, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 905491@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sebastian Ramacher <sramacher@debian.org> (supplier of updated soundtouch package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 20 Dec 2018 23:16:03 +0100
Source: soundtouch
Binary: libsoundtouch1 libsoundtouch-dev soundstretch
Architecture: source
Version: 2.1.2+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Multimedia Maintainers <debian-multimedia@lists.debian.org>
Changed-By: Sebastian Ramacher <sramacher@debian.org>
Description:
 libsoundtouch-dev - Development files for the sound stretching library
 libsoundtouch1 - Sound stretching library
 soundstretch - Stretches and pitch-shifts sound independently
Closes: 905491 905504 913894 913895
Changes:
 soundtouch (2.1.2+ds1-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release.
     - Fix double free (CVE-2018-17097). (Closes: #913895)
     - Fix assertion failure (CVE-2018-17096).
     - Fix assertion failure (CVE-2018-14045). (Closes: #905504)
     - Fix buffer overflow (CVE-2018-1000223). (Closes: #905491)
     - Fix assertion failure (CVE-2018-14044). (Closes: #905504)
     - Fix heap corruption (CVE-2018-17098). (Closes: #913894)
   * debian/watch: Update watch file for gitlab
   * debian/copyright: Repack to remove DLLs and pre-built JARs for Android.
   * debian/control: Bump Standards-Version.
Checksums-Sha1:
 471fc1cab4117549e5d63678f07bf5b2594750f7 2107 soundtouch_2.1.2+ds1-1.dsc
 aa378729319df4e3eb084a2162eebde496537643 85388 soundtouch_2.1.2+ds1.orig.tar.xz
 98b0e36cef6c720ad9bae5d9be03b00f0dcc8126 8308 soundtouch_2.1.2+ds1-1.debian.tar.xz
Checksums-Sha256:
 30e8bed17aea755eff99ffe3d8a15db65d04f99a565548428978f6fce5524af6 2107 soundtouch_2.1.2+ds1-1.dsc
 6dffac5d5718360a57f14ad9a199d61297f61c79aec58a6b93e58ff43a306733 85388 soundtouch_2.1.2+ds1.orig.tar.xz
 e991403f4139222f2eef370cdd065db4a82617c3208c2fc756e7a97541fd529a 8308 soundtouch_2.1.2+ds1-1.debian.tar.xz
Files:
 66d06b81854645f964209f68c535aaa4 2107 libs optional soundtouch_2.1.2+ds1-1.dsc
 a1f3a87feea2487c3a57255d78814f7c 85388 libs optional soundtouch_2.1.2+ds1.orig.tar.xz
 cbc18f10c7ea98477d6f2f7f972b4a60 8308 libs optional soundtouch_2.1.2+ds1-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE94y6B4F7sUmhHTOQafL8UW6nGZMFAlwcFPAACgkQafL8UW6n
GZMtnA//cnx4aG8upXfD0NI80idjySfnApLPMtezL4wXLUYIsT10eb/8e/j3MFsL
7eGmJ33Fo+tjXMC1qBa5996Kz836u0Wdjd/SrIEJfq9qG4XhMHQ7K9xS0JtvI7MK
FU8ggJkoABvfuMG5sNW6h1lD+tdB2o3scpGXgYMr51YVUO0TT7/RAN6v3FUjMBbA
hA2ESNAJJ9KDaiHUHrM4JNc3YiyvcX44KDljCohQ4QNrgPJM5WFdOLVXjtwNIWlV
con7UOWiW940AOWBel2UrhBwMFgDpJHM/ZrPsowtLm6YJIe6mJzLKUprR0Nry+dL
sHW2g9T5w991zCne5uIJ3wACH5xHodTJKh6pHGg38kwIT805/+09lfCM7D+dtlRh
OtP+ygFf+DiL8L8/gJqm0bLwm26J9LPyEdQzExQxR/W/e0rAJo4liXsylc7nA/sI
TNxkXe/NqVyezp/D37LYuMX5f6rjukaqOc0UVzlF/AfcoCBUzjZ3inemEgvvE9ET
x80pqI1p+HLJzRGmgq1YzHMoy1uvrt+n1jVDK8Ejo4s150lTYQ3F0bGfQGXJVWLd
CJwPurVHO7n3CUmqnDQ6h5ueL2RDsnoKKQ/ef4nQ3DmS1ZIz/W5jNqVnfZ+R/I4u
gX2lKachNMPuHtzIARp7aS/NeqWuzuBrqRsWEgVPyxi69YJ9BEM=
=13GQ
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: