Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
{
"binaries": [
{
"binary_version": "1:4.6~dfsg-1",
"binary_name": "ardour"
},
{
"binary_version": "1:4.6~dfsg-1",
"binary_name": "ardour-altivec"
},
{
"binary_version": "1:4.6~dfsg-1",
"binary_name": "ardour-data"
},
{
"binary_version": "1:4.6~dfsg-1",
"binary_name": "ardour-i686"
},
{
"binary_version": "1:4.6~dfsg-1",
"binary_name": "ardour3"
}
]
}
{
"binaries": [
{
"binary_version": "1:5.12.0-3ubuntu0.1",
"binary_name": "ardour"
},
{
"binary_version": "1:5.12.0-3ubuntu0.1",
"binary_name": "ardour-data"
},
{
"binary_version": "1:5.12.0-3ubuntu0.1",
"binary_name": "ardour-video-timeline"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_version": "1:5.12.0-3ubuntu4.1",
"binary_name": "ardour"
},
{
"binary_version": "1:5.12.0-3ubuntu4.1",
"binary_name": "ardour-data"
},
{
"binary_version": "1:5.12.0-3ubuntu4.1",
"binary_name": "ardour-video-timeline"
}
],
"availability": "No subscription required"
}