Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2022.5898 flac security update 16 November 2022 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: flac Publisher: Red Hat Operating System: Red Hat Resolution: Patch/Upgrade CVE Names: CVE-2021-0561 Original Bulletin: https://access.redhat.com/errata/RHSA-2022:8078 Comment: CVSS (Max): 5.5 CVE-2021-0561 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) CVSS Source: Red Hat Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: flac security update Advisory ID: RHSA-2022:8078-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8078 Issue date: 2022-11-15 CVE Names: CVE-2021-0561 ===================================================================== 1. Summary: An update for flac is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: FLAC stands for Free Lossless Audio Codec. FLAC is similar to Ogg Vorbis, but lossless. The FLAC project consists of the stream format, reference encoders and decoders in library form, a command-line program to encode and decode FLAC files, and a command-line metadata editor for FLAC files. Security Fix(es): * flac: out of bound write in append_to_verify_fifo_interleaved_ of stream_encoder.c (CVE-2021-0561) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2057776 - CVE-2021-0561 flac: out of bound write in append_to_verify_fifo_interleaved_ of stream_encoder.c 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: flac-1.3.3-10.el9.src.rpm aarch64: flac-debuginfo-1.3.3-10.el9.aarch64.rpm flac-debugsource-1.3.3-10.el9.aarch64.rpm flac-libs-1.3.3-10.el9.aarch64.rpm flac-libs-debuginfo-1.3.3-10.el9.aarch64.rpm ppc64le: flac-debuginfo-1.3.3-10.el9.ppc64le.rpm flac-debugsource-1.3.3-10.el9.ppc64le.rpm flac-libs-1.3.3-10.el9.ppc64le.rpm flac-libs-debuginfo-1.3.3-10.el9.ppc64le.rpm s390x: flac-debuginfo-1.3.3-10.el9.s390x.rpm flac-debugsource-1.3.3-10.el9.s390x.rpm flac-libs-1.3.3-10.el9.s390x.rpm flac-libs-debuginfo-1.3.3-10.el9.s390x.rpm x86_64: flac-debuginfo-1.3.3-10.el9.i686.rpm flac-debuginfo-1.3.3-10.el9.x86_64.rpm flac-debugsource-1.3.3-10.el9.i686.rpm flac-debugsource-1.3.3-10.el9.x86_64.rpm flac-libs-1.3.3-10.el9.i686.rpm flac-libs-1.3.3-10.el9.x86_64.rpm flac-libs-debuginfo-1.3.3-10.el9.i686.rpm flac-libs-debuginfo-1.3.3-10.el9.x86_64.rpm Red Hat CodeReady Linux Builder (v. 9): aarch64: flac-1.3.3-10.el9.aarch64.rpm flac-debuginfo-1.3.3-10.el9.aarch64.rpm flac-debugsource-1.3.3-10.el9.aarch64.rpm flac-devel-1.3.3-10.el9.aarch64.rpm flac-libs-debuginfo-1.3.3-10.el9.aarch64.rpm ppc64le: flac-1.3.3-10.el9.ppc64le.rpm flac-debuginfo-1.3.3-10.el9.ppc64le.rpm flac-debugsource-1.3.3-10.el9.ppc64le.rpm flac-devel-1.3.3-10.el9.ppc64le.rpm flac-libs-debuginfo-1.3.3-10.el9.ppc64le.rpm s390x: flac-1.3.3-10.el9.s390x.rpm flac-debuginfo-1.3.3-10.el9.s390x.rpm flac-debugsource-1.3.3-10.el9.s390x.rpm flac-devel-1.3.3-10.el9.s390x.rpm flac-libs-debuginfo-1.3.3-10.el9.s390x.rpm x86_64: flac-1.3.3-10.el9.x86_64.rpm flac-debuginfo-1.3.3-10.el9.i686.rpm flac-debuginfo-1.3.3-10.el9.x86_64.rpm flac-debugsource-1.3.3-10.el9.i686.rpm flac-debugsource-1.3.3-10.el9.x86_64.rpm flac-devel-1.3.3-10.el9.i686.rpm flac-devel-1.3.3-10.el9.x86_64.rpm flac-libs-debuginfo-1.3.3-10.el9.i686.rpm flac-libs-debuginfo-1.3.3-10.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-0561 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3OMatzjgjWX9erEAQirQw/+Ogspm4lU4ref0z1XUq1fPAy7tx1uP9+J gtW+XE0edEaRYkQYsBo7jtyVS9YPcSSEN6i+bhCFh8P+5D5vLvps3gUQMf801RQv M40HS+wjwdcO3R9Mg16yi6nArhnmvg19V2pWgUzqjvQdl/EGYxMtfFJC9nZNa2Pi OZe5HsW4KERMhqcSCOd2N25z6Y0PHEAJnBezm4y+pw8AFFPDX/z7sQbvXsxbrBNW uvkDz83IS7GtOMQEKytoVv9VUgM/j/wcoyb+iskkRmQ8EjQbtZYHokVlae/2B87g OC3DXhITbruQpK6WI8iNreoLK7T9wXfFLTvl8UP3nQwIAO30jbMas2ziPkRf6L+h FS8xnytVQ9alL9xxlpwvWly8igs5u/0w3brdSiZXHDz9f+20D7dkkZQhq6dla4XY wpdZbIPutynjguPtIl1TKG/WnUldYYq+7wiS9eT4zJ3ShAsi1/czQz3Mqkwsankn gxEXAV+5aQhX52RJ4fpXV7DKzDZJyCKyS+Hm0/Ne/AuYQjrxOWqVXbSjWYMOExnA oZEKqInTQ3QdrCrPBo+SkZg2P394PmClydlpCYTMExNYKVLTAkbMCKH3BRYF4cnj w3Vejd7Jd2lx2KbWEVR2tl48J4d2vVRHRe66JP1Kq8kU7Sni3WQLvwXFERueFSU6 9+iIbeADsTs= =muDp - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBY3Q48ckNZI30y1K9AQjamA//SBXlEBKLWWlxhlEKoAII+xZiueRqdmjN T+2MIL+URJxbbXM4/+I8RdDB4So2R5dcBm1vnfPY9WvHZgfGPXMXLTfUi2mpkBAv wX1/8w7iylTx8LT36fZe/178EUGk/JkhBliANBDwIsbQsbpdBCFF/2zLpri1BNrw ITGCH+m4MFCDj0hXVIkiUInd+tnxXibSUv+A2TITlyEh0O4eyC+SWB052pVPGgq+ cMFtLt3QEMEVSzAFhGvYBaql8kWaXXwqbxNKRX9m9t3sb1NBlFAlMCgSblxOL5SY 0WfvtlEj2GtHW9otpdSnxSZH9IjZf15ikQmP5qeV1jlxYGUqYoPXGy2lP0+lxkgf JUNHPV+6TRCmb9C7n7L2FudtXS+1xxaV+i38IcdfhXlebXkkPFoaUqY1VWseO4p/ rur6N5NcnA6owYuhtQNulgLaamX2yj8GFwU3bdTZ039QcU7ukPU6OQPXug6GOtr1 JGtfCPXcuRsbI+Cg0r+KxqsROs/vOiYhv4ACweB3/eDM+yfEUKlr+KBmctK4BS3w FGyvewSkAPJbRS5vmeKWoK4rvxJ02jOuuZahLR9r5DbpOpfVmSuCbArLypp/WXz6 7xpS+zyMycAncZZUWRsEjmBr1tp5NVoOy34K+kZ2Jt0B7xBb4HfBEmjgtOw3plbA 8xXgi70CJH8= =ufbq -----END PGP SIGNATURE-----