Fedora has issued an advisory today (January 6): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/N4PM4XSC7DQUG2ICWTLDQZFOXFMVL3MQ/ The issues are fixed in 1.3.2: https://xiph.org/flac/changelog.html or in this commit: https://git.xiph.org/?p=flac.git;a=commitdiff;h=c06a44969c1145242a22f75fc8fb2e8b54c55303
CC: (none) => marja11Assignee: bugsquad => rverschelde
Submitted flac-1.3.2-1.mga5 to core/updates_testing. Advisory: ========= Updated flac packages fix security vulnerabilities FLAC 1.3.2 fixes a NULL pointer dereference bug and adds bounds checking in the encoder. It also fixes various non security-relevant issues. References: - https://xiph.org/flac/changelog.html RPMs in core/updates_testing: ============================= flac-1.3.2-1.mga5 lib{64,}flac8-1.3.2-1.mga5 lib{64,}flac-devel-1.3.2-1.mga5 lib{64,}flac++6-1.3.2-1.mga5 lib{64,}flac++-devel-1.3.2-1.mga5 SRPM in core/updates_testing: ============================= flac-1.3.2-1.mga5
Assignee: rverschelde => qa-bugs
CC: (none) => davidwhodginsWhiteboard: (none) => advisory
mga5-32-ok The following 3 packages are going to be installed: - flac-1.3.2-1.mga5.i586 - libflac++6-1.3.2-1.mga5.i586 - libflac8-1.3.2-1.mga5.i586 872KB of additional disk space will be used. 468KB of packages will be retrieved. Is it ok to continue? $ flac -f --best --keep-foreign-metadata *.wav able to the play the files without issue
CC: (none) => brtians1Whiteboard: advisory => advisory mga5-32-ok
The following 3 packages are going to be installed: - flac-1.3.2-1.mga5.x86_64 - lib64flac++6-1.3.2-1.mga5.x86_64 - lib64flac8-1.3.2-1.mga5.x86_64 865KB of additional disk space will be used. 467KB of packages will be retrieved. Is it ok to continue? --------------------- ok not sure on this one. Converted WAV file without issue. Tried an ogg file and it toasted. ERROR got FLAC__STREAM_DECODER_ERROR_STATUS_LOST_SYNC while decoding FLAC input 12_-_Sangre_Dolce.ogg: ERROR: out of memory or too many metadata blocks while reading metadata in FLAC input --- anybody have some input on this one?
Status comment: (none) => need some input on this one before I okay it.
Whiteboard: advisory mga5-32-ok => advisory mga5-32-ok feedback
Ok - flac utility does not transcode from ogg. So, it worked on wav files. I think it is fine. Approving and removing the feedback flag.
Whiteboard: advisory mga5-32-ok feedback => advisory mga5-32-ok mga5-64-ok
Keywords: (none) => validated_updateCC: (none) => lewyssmith, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0074.html
Status: NEW => RESOLVEDResolution: (none) => FIXED