libaacplus: Denial of Service — GLSA 202209-13

Multiple vulnerabilities have been discovered in libaacplus, the worst of which could result in denial of service.

Affected packages

media-libs/libaacplus on all architectures
Affected versions <= 2.0.2-r3
Unaffected versions

Background

libaacplus is an HE-AAC+ v2 library, based on the reference implementation.

Description

Multiple vulnerabilities have been discovered in libaacplus. Please review the CVE identifiers referenced below for details.

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Resolution

Gentoo has discontinued suport for libaacplus. We recommend that users remove it:

 # emerge --ask --depclean "media-libs/libaacplus"
 

References

Release date
September 25, 2022

Latest revision
September 25, 2022: 1

Severity
normal

Exploitable
local and remote

Bugzilla entries