Bug 1142433 - (CVE-2019-1010222) VUL-1: CVE-2019-1010222: aubio: null pointer in filterbank by passing invalid arguments to new_aubio_filterbank
(CVE-2019-1010222)
VUL-1: CVE-2019-1010222: aubio: null pointer in filterbank by passing invalid...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.0
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/237819/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-23 06:21 UTC by Alexandros Toptsoglou
Modified: 2020-01-28 23:52 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-07-23 06:21:15 UTC
CVE-2019-1010222

aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash. The
component is: filterbank. The attack vector is: pass invalid arguments to
new_aubio_filterbank. The fixed version is: after commit
eda95c9c22b4f0b466ae94c4708765eaae6e709e.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-1010222
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010222
https://github.com/aubio/aubio/commit/eda95c9c22b4f0b466ae94c4708765eaae6e709e
https://github.com/aubio/aubio/blob/0.4.8/src/spectral/mfcc.c#L79
Comment 1 Alexandros Toptsoglou 2019-07-23 06:22:19 UTC
TW ships already a fixed version
Comment 2 Takashi Iwai 2019-07-23 09:58:32 UTC
The commit eda95c9c22b4f0b466ae94c4708765eaae6e709e was already covered by CVE-2018-19801.

Reassigned back.
Comment 3 Swamp Workflow Management 2019-07-23 11:00:11 UTC
This is an autogenerated message for OBS integration:
This bug (1142433) was mentioned in
https://build.opensuse.org/request/show/717834 15.0 / aubio
Comment 4 Swamp Workflow Management 2019-08-06 19:17:43 UTC
openSUSE-SU-2019:1834-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1137823,1142433,1142435,1142436
CVE References: CVE-2018-19802,CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224
Sources used:
openSUSE Leap 15.0 (src):    aubio-0.4.6-lp150.3.13.1, python-aubio-0.4.6-lp150.3.13.1
Comment 5 Swamp Workflow Management 2019-08-13 13:10:35 UTC
openSUSE-SU-2019:1852-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1137823,1142433,1142435,1142436
CVE References: CVE-2018-19802,CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224
Sources used:
openSUSE Backports SLE-15 (src):    aubio-0.4.6-bp150.3.15.1, python-aubio-0.4.6-bp150.3.15.1
Comment 6 Alexandros Toptsoglou 2020-01-16 14:00:11 UTC
all done. Closing
Comment 7 Swamp Workflow Management 2020-01-16 16:10:06 UTC
This is an autogenerated message for OBS integration:
This bug (1142433) was mentioned in
https://build.opensuse.org/request/show/765018 15.1 / aubio
Comment 8 Swamp Workflow Management 2020-01-28 17:14:12 UTC
openSUSE-SU-2020:0121-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1142433,1142435,1142436
CVE References: CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224
Sources used:
openSUSE Leap 15.1 (src):    aubio-0.4.6-lp151.6.7.1, python-aubio-0.4.6-lp151.6.7.1