UbuntuUpdates.org

Package "fdkaac"

Name: fdkaac

Description:

command line encoder frontend for libfdk-aac

Latest version: 1.0.0-1ubuntu0.25.04.1
Release: plucky (25.04)
Level: security
Repository: multiverse
Homepage: https://github.com/nu774/fdkaac

Links


Download "fdkaac"


Other versions of "fdkaac" in Plucky

Repository Area Version
base multiverse 1.0.0-1build1
updates multiverse 1.0.0-1ubuntu0.25.04.1

Changelog

Version: 1.0.0-1ubuntu0.25.04.1 2025-07-22 04:07:38 UTC

  fdkaac (1.0.0-1ubuntu0.25.04.1) plucky-security; urgency=medium

  * SECURITY UPDATE: Denial of Service
    - debian/patches/CVE-2022-36148.patch: Ensure fmt and desc chunks
      are seen
    - CVE-2022-36148
  * SECURITY UPDATE: Buffer Overflow
    - debian/patches/CVE-2022-37781-1.patch: Don't return more samples
      than required
    - debian/patches/CVE-2022-37781-2.patch: Add format checks
    - CVE-2022-37781
  * SECURITY UPDATE: Stack/Buffer Overflow
    - debian/patches/CVE-2023-34823-CVE-2023-34824.patch: Allocate
      correct about of memory and check return value
    - CVE-2023-34823
    - CVE-2023-34824

 -- Bruce Cable <email address hidden> Thu, 17 Jul 2025 14:59:12 +1000

CVE-2022-36148 fdkaac commit 53fe239 was discovered to contain a floating point exception (FPE) via wav_open at /src/wav_reader.c.
CVE-2022-37781 fdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at /sanitizer_common/sanitizer_common_interceptors.in
CVE-2023-34823 fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.
CVE-2023-34824 fdkaac before 1.0.5 was discovered to contain a heap buffer overflow in caf_info function in caf_reader.c.



About   -   Send Feedback to @ubuntu_updates