libaacplus: Denial of Service Multiple vulnerabilities have been discovered in libaacplus, the worst of which could result in denial of service. libaacplus 2022-09-25 2022-09-25 618000 local and remote 2.0.2-r3

libaacplus is an HE-AAC+ v2 library, based on the reference implementation.

Multiple vulnerabilities have been discovered in libaacplus. Please review the CVE identifiers referenced below for details.

Please review the referenced CVE identifiers for details.

There is no known workaround at this time.

Gentoo has discontinued suport for libaacplus. We recommend that users remove it:

# emerge --ask --depclean "media-libs/libaacplus"
CVE-2017-7603 CVE-2017-7604 CVE-2017-7605 ajak ajak