USN-5749-1: libsamplerate vulnerability
29 November 2022
libsamplerate could cause a crash if it processed a specially crafted audio file.
Releases
Packages
- libsamplerate - Audio sample rate conversion library
Details
Erik de Castro Lopo and Agostino Sarubbo discovered that libsamplerate
did not properly perform bounds checking. If a user were tricked into
processing a specially crafted audio file, an attacker could possibly
use this issue to cause a crash.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libsamplerate0
-
0.1.8-8ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.