Bugzilla – Bug 1142435
VUL-1: CVE-2019-1010224: aubio: null pointer in onset leading to DOS
Last modified: 2020-02-05 07:46:48 UTC
CVE-2019-1010224 aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash (DoS). The component is: onset. The fixed version is: after commit e4e0861cffbc8d3a53dcd18f9ae85797690d67c7. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-1010224 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010224 https://github.com/aubio/aubio/commit/e4e0861cffbc8d3a53dcd18f9ae85797690d67c7 https://github.com/aubio/aubio/blob/0.4.8/src/onset/onset.c#L59
TW ships already version 0.4.9
The fix is submitted. Reassigned back.
This is an autogenerated message for OBS integration: This bug (1142435) was mentioned in https://build.opensuse.org/request/show/717834 15.0 / aubio
openSUSE-SU-2019:1834-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1137823,1142433,1142435,1142436 CVE References: CVE-2018-19802,CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224 Sources used: openSUSE Leap 15.0 (src): aubio-0.4.6-lp150.3.13.1, python-aubio-0.4.6-lp150.3.13.1
openSUSE-SU-2019:1852-1: An update that fixes four vulnerabilities is now available. Category: security (moderate) Bug References: 1137823,1142433,1142435,1142436 CVE References: CVE-2018-19802,CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224 Sources used: openSUSE Backports SLE-15 (src): aubio-0.4.6-bp150.3.15.1, python-aubio-0.4.6-bp150.3.15.1
Leap 15.1 seems to miss the fix. Reassigning back.
(In reply to Alexandros Toptsoglou from comment #6) > Leap 15.1 seems to miss the fix. Reassigning back. Hm, OK, now submitted to 15.1:Update. For Leap, did we need to submit the same thing to both Leap 15.0 and 15.1? Now it doesn't matter, but I'd like to confirm that for future.
(In reply to Takashi Iwai from comment #7) > (In reply to Alexandros Toptsoglou from comment #6) > > Leap 15.1 seems to miss the fix. Reassigning back. > > Hm, OK, now submitted to 15.1:Update. > > For Leap, did we need to submit the same thing to both Leap 15.0 and 15.1? > Now it doesn't matter, but I'd like to confirm that for future. Unless a package is inherited from SLE, we need a submission for each supported version. The difference in openSUSE is that we also accept one submission which contains fixes for more than one codestream.
Thanks for clarification. Now reassigned back to security team.
This is an autogenerated message for OBS integration: This bug (1142435) was mentioned in https://build.opensuse.org/request/show/765018 15.1 / aubio
openSUSE-SU-2020:0121-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1142433,1142435,1142436 CVE References: CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224 Sources used: openSUSE Leap 15.1 (src): aubio-0.4.6-lp151.6.7.1, python-aubio-0.4.6-lp151.6.7.1
done