Out-of-bounds read in Pixel - CVE-2021-0561

 

Out-of-bounds read in Pixel - CVE-2021-0561

Published: November 15, 2022


Vulnerability identifier: #VU69342
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-0561
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition within the append_to_verify_fifo_interleaved_ in stream_encoder.c in Media Framework. A local application can trigger an out-of-bounds read error and read contents of memory on the system.


Affected software

Pixel
Amazon Linux AMI
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Ubuntu
openEuler
Fedora
My Cloud OS 5
WD Cloud
My Cloud EX2100
My Cloud DL4100
My Cloud DL2100
My Cloud Mirror G2
My Cloud PR2100
My Cloud PR4100
My Cloud EX4100
My Cloud EX2 Ultra
My Cloud
flac (Ubuntu package)
libflac++6 (Ubuntu package)
libflac++6v5 (Ubuntu package)
libflac8 (Ubuntu package)
flac
flac-devel
flac-debugsource
flac-debuginfo
xmms-flac
flac-help
flac (Red Hat package)
cflinuxfs3

How to mitigate CVE-2021-0561

Install updates from vendor's website.

Pixel - update to 11 2021-06-05
flac (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.2-1ubuntu0.1, 1.3.3-1ubuntu0.1, 1.3.3-2ubuntu0.1
libflac++6 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libflac++6v5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.2-1ubuntu0.1, 1.3.3-1ubuntu0.1, 1.3.3-2ubuntu0.1
libflac8 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1.3.2-1ubuntu0.1, 1.3.3-1ubuntu0.1, 1.3.3-2ubuntu0.1
cflinuxfs3 - update to 0.337.0
flac - update to 1.3.3-5
flac-devel - update to 1.3.3-5
flac-debugsource - update to 1.3.3-5
flac-debuginfo - update to 1.3.3-5
xmms-flac - update to 1.3.3-5
flac-help - update to 1.3.3-5
flac (Red Hat package) - update to 1.3.3-10.el9
flac - update to 1.3.4
flac - update to 1.3.4-1
flac - addressed in versions 1.3.4-1.fc35, 1.3.4-1.fc36
My Cloud OS 5 - update to 5.25.124

External References

Related Security Bulletins