git: 2fce4c1321ed - main - security/vuxml: Document CVE-2021-3756 for audio/libmysofa
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sun, 20 Feb 2022 13:18:44 UTC
The branch main has been updated by jhale:
URL: https://cgit.FreeBSD.org/ports/commit/?id=2fce4c1321eddbe459282f2506161439f92f9c85
commit 2fce4c1321eddbe459282f2506161439f92f9c85
Author: Jason E. Hale <jhale@FreeBSD.org>
AuthorDate: 2022-02-20 12:54:21 +0000
Commit: Jason E. Hale <jhale@FreeBSD.org>
CommitDate: 2022-02-20 13:18:29 +0000
security/vuxml: Document CVE-2021-3756 for audio/libmysofa
---
security/vuxml/vuln-2022.xml | 28 ++++++++++++++++++++++++++++
1 file changed, 28 insertions(+)
diff --git a/security/vuxml/vuln-2022.xml b/security/vuxml/vuln-2022.xml
index 33b651db8211..69bdc14a7672 100644
--- a/security/vuxml/vuln-2022.xml
+++ b/security/vuxml/vuln-2022.xml
@@ -1,3 +1,31 @@
+ <vuln vid="4d763c65-9246-11ec-9aa3-4ccc6adda413">
+ <topic>libmysoft -- Heap-based buffer overflow vulnerability</topic>
+ <affects>
+ <package>
+ <name>libmysofa</name>
+ <range><lt>1.2.1.13</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Zhengjie Du reports:</p>
+ <blockquote cite="https://huntr.dev/bounties/7ca8d9ea-e2a6-4294-af28-70260bb53bc1/">
+ <p>There are some heap-buffer-overflows in mysofa2json of
+ libmysofa. They are in function loudness, mysofa_check and
+ readOHDRHeaderMessageDataLayout.</p>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2021-3756</cvename>
+ <url>https://www.huntr.dev/bounties/7ca8d9ea-e2a6-4294-af28-70260bb53bc1/</url>
+ </references>
+ <dates>
+ <discovery>2021-09-27</discovery>
+ <entry>2022-02-20</entry>
+ </dates>
+ </vuln>
+
<vuln vid="27bf9378-8ffd-11ec-8be6-d4c9ef517024">
<topic>MariaDB -- Multiple vulnerabilities</topic>
<affects>