Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:5.12.0-3ubuntu0.1", "binary_name": "ardour" }, { "binary_version": "1:5.12.0-3ubuntu0.1", "binary_name": "ardour-data" }, { "binary_version": "1:5.12.0-3ubuntu0.1", "binary_name": "ardour-dbgsym" }, { "binary_version": "1:5.12.0-3ubuntu0.1", "binary_name": "ardour-video-timeline" } ], "availability": "No subscription required" }
{ "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:5.12.0-3ubuntu4.1", "binary_name": "ardour" }, { "binary_version": "1:5.12.0-3ubuntu4.1", "binary_name": "ardour-data" }, { "binary_version": "1:5.12.0-3ubuntu4.1", "binary_name": "ardour-dbgsym" }, { "binary_version": "1:5.12.0-3ubuntu4.1", "binary_name": "ardour-video-timeline" } ], "availability": "No subscription required" }