MGASA-2020-0476

Source
https://advisories.mageia.org/MGASA-2020-0476.html
Import Source
https://advisories.mageia.org/MGASA-2020-0476.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0476
Upstream
Published
2020-12-29T11:57:17Z
Modified
2026-04-16T04:41:32Z
Summary
Updated jackit packages fix security vulnerability
Details

posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor (CVE-2019-13351).

References
Credits

Affected packages

Mageia:7 / jackit

Package

Name
jackit
Purl
pkg:rpm/mageia/jackit?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.12-2.1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2020-0476.json"