MGASA-2019-0078
Dashboard / Vulnerabilities / MGASA-2019-0078
MGASA-2019-0078
Summary: Updated mad packages fix security vulnerability
Details: The mad_decoder_run function in decoder.c in libmad 0.15.1b allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file (CVE-2017-11552). The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file (CVE-2018-7263).
References: https://advisories.mageia.org/MGASA-2019-0078.html, https://bugs.mageia.org/show_bug.cgi?id=23698, https://lists.fedoraproject.org/archives/list/[email protected]/thread/CCLUAGAEWOQKRY2C6HLTXT5WWTWSTNIP/
Affected packages
Package
Name: mad
Purl: pkg:rpm/mageia/mad?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
