• [SECURITY] [DSA 4125-1] wavpack security update

    From Sebastien Delafond@1:229/2 to All on Tue Feb 27 21:40:01 2018
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4125-1 [email protected] https://www.debian.org/security/ Sebastien Delafond February 27, 2018 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : wavpack
    CVE ID : CVE-2018-6767 CVE-2018-7253 CVE-2018-7254
    Debian Bug : 889274 889276 889559

    Joonun Jang discovered several problems in wavpack, an audio
    compression format suite. Incorrect processing of input resulted in
    several heap- and stack-based buffer overflows, leading to application
    crash or potential code execution.

    For the stable distribution (stretch), these problems have been fixed
    in version 5.0.0-2+deb9u1.

    We recommend that you upgrade your wavpack packages.

    For the detailed security status of wavpack please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/wavpack

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAlqVvW0ACgkQEL6Jg/PV nWTMkAgAyTrGAACeXh62h6au9KIV4ugKzL+47rcSMxxm3WPbapcVZgBHksRGIl+a JjEsITs18EIRhWBa2J7yhraKFppS23y4reKzZJvfi2qWEtz1i/pPFdhVr8N+XnKG adEK8lkv8MQEolSBCeyK3h1eog+I06yL2EY76gFf+B1PSOEBlf2m4+4R1vVpQmlL Ata3ouxMNUQql7IyB1QFd+b/5ALgWIMSPxxvTV2Lr1OTAs2BgdQhliHd2NWKCEHA 56nPOeSPbjZ3LT7jDKpnthaJSk1mD3E4woe5GWy9D6vS6ukgKcajOIZW70ezLmZt G8nFidrbt2yAwkJhFmXy2h1uUjH7Og==
    =uqxj
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)