openSUSE-SU-2018:0544-1
Dashboard / Vulnerabilities / openSUSE-SU-2018:0544-1
openSUSE-SU-2018:0544-1
Summary: Security update for lame
Details: This update for lame fixes the following issues: Lame was updated to version 3.100: * Improved detection of MPEG audio data in RIFF WAVE files. sf#3545112 Invalid sampling detection * New switch --gain <decibel>, range -20.0 to +12.0, a more convenient way to apply Gain adjustment in decibels, than the use of --scale <factor>. * Fix for sf#3558466 Bug in path handling * Fix for sf#3567844 problem with Tag genre * Fix for sf#3565659 no progress indication with pipe input * Fix for sf#3544957 scale (empty) silent encode without warning * Fix for sf#3580176 environment variable LAMEOPT doesn't work anymore * Fix for sf#3608583 input file name displayed with wrong character encoding (on windows console with CP_UTF8) * Fix dereference NULL and Buffer not NULL terminated issues. (CVE-2017-15019 bsc#1082317 CVE-2017-13712 bsc#1082399 CVE-2015-9100 bsc#1082401) * Fix dereference of a null pointer possible in loop. * Make sure functions with SSE instructions maintain their own properly aligned stack. Thanks to Fabian Greffrath * Multiple Stack and Heap Corruptions from Malicious File. (CVE-2017-9872 bsc#1082391 CVE-2017-9871 bsc#1082392 CVE-2017-9870 bsc#1082393 CVE-2017-9869 bsc#1082395 CVE-2017-9411 bsc#1082397 CVE-2015-9101 bsc#1082400) * CVE-2017-11720: Fix a division by zero vulnerability. (bsc#1082311) * CVE-2017-9410: Fix fill_buffer_resample function in libmp3lame/util.c heap-based buffer over-read and ap (bsc#1082333) * CVE-2017-9411: Fix fill_buffer_resample function in libmp3lame/util.c invalid memory read and application crash (bsc#1082397) * CVE-2017-9412: FIx unpack_read_samples function in frontend/get_audio.c invalid memory read and application crash (bsc#1082340) * Fix clip detect scale suggestion unaware of scale input value * HIP decoder bug fixed: decoding mixed blocks of lower sample frequency Layer3 data resulted in internal buffer overflow. * Add lame_encode_buffer_interleaved_int()
References: https://lists.opensuse.org/archives/list/[email protected]/thread/KH623JZ3J2KZAJL44XIFV3PAHON2NVKG/#KH623JZ3J2KZAJL44XIFV3PAHON2NVKG, https://bugzilla.suse.com/1082311, https://bugzilla.suse.com/1082317, https://bugzilla.suse.com/1082333, https://bugzilla.suse.com/1082340, https://bugzilla.suse.com/1082391, https://bugzilla.suse.com/1082392, https://bugzilla.suse.com/1082393, https://bugzilla.suse.com/1082395, https://bugzilla.suse.com/1082397, https://bugzilla.suse.com/1082399, https://bugzilla.suse.com/1082400, https://bugzilla.suse.com/1082401, https://www.suse.com/security/cve/CVE-2015-9100, https://www.suse.com/security/cve/CVE-2015-9101, https://www.suse.com/security/cve/CVE-2017-11720, https://www.suse.com/security/cve/CVE-2017-13712, https://www.suse.com/security/cve/CVE-2017-15019, https://www.suse.com/security/cve/CVE-2017-9410, https://www.suse.com/security/cve/CVE-2017-9411, https://www.suse.com/security/cve/CVE-2017-9412, https://www.suse.com/security/cve/CVE-2017-9869, https://www.suse.com/security/cve/CVE-2017-9870, https://www.suse.com/security/cve/CVE-2017-9871, https://www.suse.com/security/cve/CVE-2017-9872
Affected packages
Package
Name: lame
Purl: pkg:rpm/suse/lame&distro=SUSE%20Package%20Hub%2012%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
