Bug#911584: libopenmpt: out of bounds memory read in MED files

2018-10-26 Thread Moritz Mühlenhoff
On Mon, Oct 22, 2018 at 09:44:27AM +0100, James Cowgill wrote:
> Source: libopenmpt
> Version: 0.2.7025~beta20.1-1
> Severity: important
> Tags: security upstream fixed-upstream
> 
> Hi,
> 
> Upstream 0.3.13 released a fix for an out of bound read in malformed MED
> files. It affects stretch.

Doesn't warrant a DSA, but we can fix it along if there's a more severe
issue in the future (or via point release)

Cheers,
Moritz



Bug#911584: libopenmpt: out of bounds memory read in MED files

2018-10-22 Thread James Cowgill
Source: libopenmpt
Version: 0.2.7025~beta20.1-1
Severity: important
Tags: security upstream fixed-upstream

Hi,

Upstream 0.3.13 released a fix for an out of bound read in malformed MED
files. It affects stretch.

Announcement:
https://lib.openmpt.org/libopenmpt/2018/10/21/security-updates-0.3.13-0.2.10933-beta36-0.2.7561-beta20.5-p11-0.2.7386-beta20.3-p14/

Upstream commit which fixes this:
https://source.openmpt.org/browse/openmpt/trunk/?op=revision=10903

James



signature.asc
Description: OpenPGP digital signature