Fedora has issued an advisory on November 22: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PYXWUCWTDAITTQHM72BGA2ENVXC7G5M/ The problem was already fixed in Cauldron so it only affects Mageia 9. Fix: https://github.com/libsndfile/libsndfile/commit/4755f5bd7854611d92ad0f1295587b439f9950ba
CVE: (none) => CVE-2024-50612Status comment: (none) => Patch available from Fedora and upstreamSource RPM: (none) => libsndfile-1.2.0-3.1.mga9.src.rpm
In Cauldron already: Nov 18 2024 by daviddavid - fix crash in in ogg vorbis (CVE-2024-50612) The CVE matches, this looks like the correction referred to. Assigning globally to apply the update for Mageia 9. Advisory etc.
Status comment: Patch available from Fedora and upstream => Patch available from Fedora and upstream (applied)Assignee: bugsquad => pkg-bugs
Assigning to QA, Packages in 9/Core/Updates_testing: ====================== libsndfile-devel-1.2.0-3.2.mga9 libsndfile1-1.2.0-3.2.mga9 lib64sndfile-devel-1.2.0-3.2.mga9 lib64sndfile1-1.2.0-3.2.mga9 libsndfile-progs-1.2.0-3.2.mga9 From SRPMS libsndfile-1.2.0-3.2.mga9.src.rpm
CC: (none) => geiger.david68210
Status comment: Patch available from Fedora and upstream (applied) => (none)Assignee: pkg-bugs => qa-bugs
Keywords: (none) => advisory
RH x86_64 sndfile-convert poc-libsndfile a.ogg Violación de segmento (`core' generado) LC_ALL=C urpmi --auto --auto-update adding 3 new rpms not available in existing hdlist replacing /var/cache/urpmi/partial/synthesis.hdlist.cz with synthesis.hdlist.cz.tmp updating /var/cache/urpmi/partial/MD5SUM updated medium "QA Testing (64-bit)" medium "Core Release (distrib1)" is up-to-date medium "Core Updates (distrib3)" is up-to-date medium "Nonfree Release (distrib11)" is up-to-date medium "Nonfree Updates (distrib13)" is up-to-date medium "Tainted Release (distrib21)" is up-to-date medium "Tainted Updates (distrib23)" is up-to-date medium "Core 32bit Release (distrib31)" is up-to-date medium "Core 32bit Updates (distrib32)" is up-to-date medium "Nonfree 32bit Release (distrib36)" is up-to-date medium "Nonfree 32bit Updates (distrib37)" is up-to-date medium "Tainted 32bit Release (distrib41)" is up-to-date medium "Tainted 32bit Updates (distrib42)" is up-to-date installing libsndfile-progs-1.2.0-3.2.mga9.x86_64.rpm lib64sndfile1-1.2.0-3.2.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/2: lib64sndfile1 ################################################################################################## 2/2: libsndfile-progs ################################################################################################## 1/2: removing libsndfile-progs-1.2.0-3.1.mga9.x86_64 ################################################################################################## 2/2: removing lib64sndfile1-1.2.0-3.1.mga9.x86_64 ################################################################################################## sndfile-convert poc-libsndfile a.ogg produce empty output
Whiteboard: (none) => MGA9-64-OKCC: (none) => andrewsfarm
RH x86_64 additional test sndfile-info 01\ -\ \ -\ Mozart\ Piano\ Concierto\ Num\ 21.flac ======================================== File : 01 - - Mozart Piano Concierto Num 21.flac Length : 14429000 FLAC Stream Metadata Channels : 2 Sample rate : 44100 Frames : 6804924 Bit width : 16 Seektable Metadata Vorbis Comment Metadata title : Mozart Piano Concierto Num 21 album : La Musica mas Hermosa del Mundo tracknumber : 1 genre : Unknown Padding Metadata End ---------------------------------------- Sample Rate : 44100 Frames : 6804924 Channels : 2 Format : 0x00170002 Sections : 1 Seekable : TRUE Duration : 00:02:34.307 Signal Max : 32380 (-0.10 dB) sndfile-play 01\ -\ \ -\ Mozart\ Piano\ Concierto\ Num\ 21.flac Playing 01 - - Mozart Piano Concierto Num 21.flac OK
Validating.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0373.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED