Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.131103
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2015-0408)
Resumen:The remote host is missing an update for the 'audiofile' package(s) announced via the MGASA-2015-0408 advisory.
Descripción:Summary:
The remote host is missing an update for the 'audiofile' package(s) announced via the MGASA-2015-0408 advisory.

Vulnerability Insight:
When libaudiofile is used to change both the number of channels of an
audio file (e.g. from stereo to mono) and the sample format (e.g. from
16-bit samples to 8-bit samples), the output file will contain corrupted
data. If the new sample format is smaller than the old one, there is a
risk of buffer overflow: e.g. when the input file has 16-bit samples and
the output file has 8-bit samples, afReadFrames will treat the buffer to
read the samples (argument void *data) as a pointer to int16_t instead of
int8_t, therefore it will write past its end (CVE-2015-7747).

Affected Software/OS:
'audiofile' package(s) on Mageia 5.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-7747
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170387.html
http://www.openwall.com/lists/oss-security/2015/10/06/2
http://www.ubuntu.com/usn/USN-2787-1
https://bugs.launchpad.net/ubuntu/+source/audiofile/+bug/1502721
https://github.com/ccrisan/motioneyeos/blob/master/package/audiofile/0008-CVE-2015-7747.patch
https://www.openwall.com/lists/oss-security/2015/10/08/1
CopyrightCopyright (C) 2015 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.