Bug 387731 (CVE-2008-2109) - VUL-0: libid3tag overflow
Summary: VUL-0: libid3tag overflow
Status: RESOLVED FIXED
Alias: CVE-2008-2109
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2008-2109: CVSS v2 Base Score: 5....
Keywords:
Depends on:
Blocks:
 
Reported: 2008-05-07 13:15 UTC by Sebastian Krahmer
Modified: 2018-03-18 14:10 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2008-05-07 13:15:08 UTC
Theres a buffer overflow in libid3tag which gentoo is going
to announce. Patch etc is here:

http://bugs.gentoo.org/show_bug.cgi?id=210564
Comment 1 Matthias Weckbecker 2008-05-08 06:49:04 UTC
======================================================
Name: CVE-2008-2109
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2109
Reference: CONFIRM:http://bugs.gentoo.org/show_bug.cgi?id=210564
Reference: MLIST:[mad-dev] 20080112 Initite loop bug in libid3tag-0.15.0b
Reference: URL:http://www.mars.org/mailman/public/mad-dev/2008-January/001366.html

field.c in the libid3tag 0.15.0b library allows context-dependent
attackers to cause a denial of service (CPU consumption) via an
ID3_FIELD_TYPE_STRINGLIST field that ends in '\0', which triggers an
infinite loop.
Comment 2 Takashi Iwai 2008-05-08 14:37:16 UTC
The fixed packages are submitted now.  Tested on 11.0b2.

Do I need to create patchinfo, or would you security team do?
Comment 3 Matthias Weckbecker 2008-05-08 14:41:34 UTC
One of the security team members will do it as soon as possible. (acutally)
Comment 4 Takashi Iwai 2008-05-08 14:49:52 UTC
OK, reassigned to security team, then.  Thanks.
Comment 5 Ludwig Nussel 2008-05-09 09:40:39 UTC
IMO this is not a security issue after all. The id3 tag parser runs into an endless of small allocations. It will eventually stop or get killed due to oom. This might be annoying but unless we have a server designed to handle arbitrary mp3 I'd not call this a security issue but just a regular bug. On SLE10 for example there isn't even an application we ship that uses libid3tag AFAICS. So we can skip this update from a security PoV.
Comment 6 Marcus Meissner 2008-05-09 13:01:33 UTC
yes, I agree.

Takashi, you can remove the submissions for the old prodxucts again
Comment 7 Takashi Iwai 2008-05-09 13:48:12 UTC
Done.  Fixed only on STABLE now.
Comment 8 Sebastian Krahmer 2008-05-13 11:42:37 UTC
So, if STABLE is sufficient, this bug can be closed.
Comment 9 Ludwig Nussel 2008-05-15 08:51:39 UTC
well, then just do it
Comment 10 Thomas Biege 2009-10-14 00:51:01 UTC
CVE-2008-2109: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Comment 12 Swamp Workflow Management 2018-03-16 20:09:17 UTC
SUSE-SU-2018:0715-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1081959,1081961,1081962,387731
CVE References: CVE-2004-2779,CVE-2008-2109,CVE-2017-11550,CVE-2017-11551
Sources used:
SUSE Linux Enterprise Software Development Kit 11-SP4 (src):    libid3tag-0.15.1b-132.3.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    libid3tag-0.15.1b-132.3.1
Comment 13 Swamp Workflow Management 2018-03-16 20:15:48 UTC
SUSE-SU-2018:0722-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1081959,1081961,1081962,387731
CVE References: CVE-2004-2779,CVE-2008-2109,CVE-2017-11550,CVE-2017-11551
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP3 (src):    libid3tag-0.15.1b-184.3.1
SUSE Linux Enterprise Workstation Extension 12-SP2 (src):    libid3tag-0.15.1b-184.3.1
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    libid3tag-0.15.1b-184.3.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    libid3tag-0.15.1b-184.3.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    libid3tag-0.15.1b-184.3.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    libid3tag-0.15.1b-184.3.1
Comment 14 Swamp Workflow Management 2018-03-18 14:10:58 UTC
openSUSE-SU-2018:0735-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 1081959,1081961,1081962,387731
CVE References: CVE-2004-2779,CVE-2008-2109,CVE-2017-11550,CVE-2017-11551
Sources used:
openSUSE Leap 42.3 (src):    libid3tag-0.15.1b-188.3.1