Bug 1142436 - (CVE-2019-1010223) VUL-0: CVE-2019-1010223: aubio buffer overflow in tempo
(CVE-2019-1010223)
VUL-0: CVE-2019-1010223: aubio buffer overflow in tempo
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.0
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/237820/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-23 06:30 UTC by Alexandros Toptsoglou
Modified: 2020-01-28 23:52 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-07-23 06:30:18 UTC
CVE-2019-1010223

aubio 0.4.8 and earlier is affected by: Buffer Overflow. The impact is: buffer
overflow in strcpy. The component is: tempo. The fixed version is: after commit
b1559f4c9ce2b304d8d27ffdc7128b6795ca82e5.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-1010223
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010223
https://github.com/aubio/aubio/blob/0.4.8/src/tempo/tempo.c#L208
https://github.com/aubio/aubio/commit/b1559f4c9ce2b304d8d27ffdc7128b6795ca82e5
Comment 1 Takashi Iwai 2019-07-23 10:00:19 UTC
The commit b1559f4c9ce2b304d8d27ffdc7128b6795ca82e5 was already covered by CVE-2018-19800.

Reassigned back.
Comment 2 Swamp Workflow Management 2019-07-23 11:00:18 UTC
This is an autogenerated message for OBS integration:
This bug (1142436) was mentioned in
https://build.opensuse.org/request/show/717834 15.0 / aubio
Comment 3 Swamp Workflow Management 2019-08-06 19:17:56 UTC
openSUSE-SU-2019:1834-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1137823,1142433,1142435,1142436
CVE References: CVE-2018-19802,CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224
Sources used:
openSUSE Leap 15.0 (src):    aubio-0.4.6-lp150.3.13.1, python-aubio-0.4.6-lp150.3.13.1
Comment 4 Swamp Workflow Management 2019-08-13 13:10:50 UTC
openSUSE-SU-2019:1852-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1137823,1142433,1142435,1142436
CVE References: CVE-2018-19802,CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224
Sources used:
openSUSE Backports SLE-15 (src):    aubio-0.4.6-bp150.3.15.1, python-aubio-0.4.6-bp150.3.15.1
Comment 5 Alexandros Toptsoglou 2020-01-16 14:00:50 UTC
all done. Closing
Comment 6 Swamp Workflow Management 2020-01-16 16:10:13 UTC
This is an autogenerated message for OBS integration:
This bug (1142436) was mentioned in
https://build.opensuse.org/request/show/765018 15.1 / aubio
Comment 7 Swamp Workflow Management 2020-01-28 17:14:25 UTC
openSUSE-SU-2020:0121-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1142433,1142435,1142436
CVE References: CVE-2019-1010222,CVE-2019-1010223,CVE-2019-1010224
Sources used:
openSUSE Leap 15.1 (src):    aubio-0.4.6-lp151.6.7.1, python-aubio-0.4.6-lp151.6.7.1