Bug 488364

Summary: CVE-2009-0186 libsndfile: overflows may lead to execution of arbitrary code [epel-5]
Product: [Fedora] Fedora EPEL Reporter: Vincent Danen <vdanen>
Component: libsndfileAssignee: Andreas Thienemann <andreas>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: low    
Version: el5CC: andreas, mastahnke, mhlavink, michel
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: ActualBug
Fixed In Version: libsndfile-1.0.17-3.el5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-07-21 12:24:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 488361    
Attachments:
Description Flags
patch from upstream none

Description Vincent Danen 2009-03-03 21:51:22 UTC
epel-5 tracking bug: see blocks bug list for full details of the security issue(s).



[bug automatically created by: add-tracking-bugs]

Comment 1 Michal Hlavinka 2010-07-07 13:34:13 UTC
Created attachment 430067 [details]
patch from upstream

Comment 2 Michel Lind 2010-07-07 23:18:23 UTC
(In reply to comment #1)
> Created an attachment (id=430067) [details]
> patch from upstream    

Thanks; building now. Oddly, the libsndfile-1_0_17-3_el5 tag already exists in CVS, even though the spec file was still at -2 -- since CVS was still at -2 and there was no Koji build for -3, I've re-tagged my build as -3.

Michal, since you're already maintaining the EL-6 branch, I'll defer to you for EL-5 updates once you get co-maintainership.

Comment 3 Fedora Update System 2010-07-07 23:23:09 UTC
libsndfile-1.0.17-3.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/libsndfile-1.0.17-3.el5

Comment 4 Fedora Update System 2010-07-09 05:54:06 UTC
libsndfile-1.0.17-3.el5 has been pushed to the Fedora EPEL 5 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update libsndfile'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/libsndfile-1.0.17-3.el5

Comment 5 Fedora Update System 2010-07-21 12:24:21 UTC
libsndfile-1.0.17-3.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.