[ubuntu/xenial-security] pulseaudio 1:8.0-0ubuntu3.14 (Accepted)

Avital Ostromich avital.ostromich at canonical.com
Thu Sep 17 21:32:59 UTC 2020


pulseaudio (1:8.0-0ubuntu3.14) xenial-security; urgency=medium

  * SECURITY UPDATE: potential double-free in the Bluez 5 module (LP: #1884738)
    - d/p/0511-bluetooth-bluez5-fix-double-free-in-pa__init.patch:
      Only free modargs once in each of
      src/modules/bluetooth/module-bluez5-device.c and
      src/modules/bluetooth/module-bluez5-discover.c, patch thanks to Ratchanan
      Srirattanamet.
    - d/p/0512-bluetooth-bluez5-fix-double-free-2.patch: Initialize pointer
      before dereferencing in fail condition.
    - CVE-2020-15710

Date: 2020-09-17 16:10:20.791532+00:00
Changed-By: Avital Ostromich <avital.ostromich at canonical.com>
https://launchpad.net/ubuntu/+source/pulseaudio/1:8.0-0ubuntu3.14
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list