Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
{
"binaries": [
{
"binary_name": "ardour",
"binary_version": "1:4.6~dfsg-1"
},
{
"binary_name": "ardour-altivec",
"binary_version": "1:4.6~dfsg-1"
},
{
"binary_name": "ardour-data",
"binary_version": "1:4.6~dfsg-1"
},
{
"binary_name": "ardour-i686",
"binary_version": "1:4.6~dfsg-1"
},
{
"binary_name": "ardour3",
"binary_version": "1:4.6~dfsg-1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ardour",
"binary_version": "1:5.12.0-3ubuntu0.1"
},
{
"binary_name": "ardour-data",
"binary_version": "1:5.12.0-3ubuntu0.1"
},
{
"binary_name": "ardour-video-timeline",
"binary_version": "1:5.12.0-3ubuntu0.1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ardour",
"binary_version": "1:5.12.0-3ubuntu4.1"
},
{
"binary_name": "ardour-data",
"binary_version": "1:5.12.0-3ubuntu4.1"
},
{
"binary_name": "ardour-video-timeline",
"binary_version": "1:5.12.0-3ubuntu4.1"
}
]
}