MGASA-2018-0019
Dashboard / Vulnerabilities / MGASA-2018-0019
Summary: Updated mad packages fix security vulnerability
Details: The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file (CVE-2017-8373). The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file (CVE-2017-8374).
References: https://advisories.mageia.org/MGASA-2018-0019.html, https://bugs.mageia.org/show_bug.cgi?id=20773, http://openwall.com/lists/oss-security/2017/05/01/8, http://openwall.com/lists/oss-security/2017/05/01/9, https://security-tracker.debian.org/tracker/CVE-2017-8373, https://security-tracker.debian.org/tracker/CVE-2017-8374
Affected packages
Package
Name: mad
Purl: pkg:rpm/mageia/mad?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
