Debian Ardour vulnerabilities

3 known vulnerabilities affecting debian/ardour.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2020-22617CRITICALCVSS 9.8fixed in ardour 1:6.0.0~ds0-1 (bookworm)2020
CVE-2020-22617 [CRITICAL] CVE-2020-22617: ardour - Ardour v5.12 contains a use-after-free vulnerability in the component ardour/lib... Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext. Scope: local bookworm: resolved (fixed in 1:6.0.0~ds0-1) bullseye: resolved (fixed in 1:6.0.0~ds0-1) forky: resolved (fixed in 1:6.0.0~ds0-1) sid: resolved (fixed in 1:6.0.0~ds0-1) trixie: resolved (fixed in 1:6.0.0~ds0-1)
debian
CVE-2010-3349LOWCVSS 6.9fixed in ardour 1:2.8.11-2 (bookworm)2010
CVE-2010-3349 [MEDIUM] CVE-2010-3349: ardour - Ardour 2.8.11 places a zero-length directory name in the LD_LIBRARY_PATH, which ... Ardour 2.8.11 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. Scope: local bookworm: resolved (fixed in 1:2.8.11-2) bullseye: resolved (fixed in 1:2.8.11-2) forky: resolved (fixed in 1:2.8.11-2) sid: resolved (fixed in 1:2.8.11-2) trixie: resolv
debian
CVE-2007-4974MEDIUMCVSS 7.5fixed in ardour 1:2.1-1.1 (bookworm)2007
CVE-2007-4974 [HIGH] CVE-2007-4974: ardour - Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17... Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data containing a block with a size that exceeds the previous block size. Scope: local bookworm: resolved (fixed in 1:2.1-1.1) bullseye: resolved (fixed in 1:2.1-1.1) forky: resolved (fixed
debian