Bug 906831 (CVE-2014-8962) - VUL-0: CVE-2014-8962 flac: stack overflow may result in arbitrary code execution
Summary: VUL-0: CVE-2014-8962 flac: stack overflow may result in arbitrary code execution
Status: RESOLVED FIXED
Alias: CVE-2014-8962
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Deadline: 2014-12-26
Assignee: Takashi Iwai
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/110973/
Whiteboard: maint:released:sle10-sp3:59826 maint:...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-11-24 12:40 UTC by Johannes Segitz
Modified: 2015-02-19 02:33 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-11-24 12:40:46 UTC
rh#1167236

There're currently no publicly availble details about this issue:
The commit will be included in flac 1.3.1.

https://git.xiph.org/?p=flac.git;a=patch;h=5b3033a2b355068c11fe637e14ac742d273f076e

I will add more details once we have them. Maintained for SLE 10 SP3 (Terradata), otherwise only openSUSE. Maybe we will switch this to VUL-1.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1167236
http://lists.xiph.org/pipermail/flac-dev/2014-November/005185.html
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8962
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8962
Comment 1 Swamp Workflow Management 2014-11-24 23:00:37 UTC
bugbot adjusting priority
Comment 2 Johannes Segitz 2014-11-25 09:19:09 UTC
A stack overflow which may result in arbitrary code execution, can be triggered by passing a maliciously crafted .flac file to the libFLAC decoder.

Affected version: libFLAC <= 1.3.0

Fixed version: libFLAC >= 1.3.1

Credit: vulnerability report from Michele Spagnuolo of Google Security Team <mikispag AT google.com>

Fix is in https://git.xiph.org/?p=flac.git;a=commit;h=5b3033a2b355068c11fe637e14ac742d273f076e
Comment 4 Bernhard Wiedemann 2014-11-26 12:00:23 UTC
This is an autogenerated message for OBS integration:
This bug (906831) was mentioned in
https://build.opensuse.org/request/show/263101 13.1 / flac
Comment 6 Bernhard Wiedemann 2014-11-26 14:00:22 UTC
This is an autogenerated message for OBS integration:
This bug (906831) was mentioned in
https://build.opensuse.org/request/show/263124 13.2 / flac
Comment 7 Bernhard Wiedemann 2014-11-26 15:00:19 UTC
This is an autogenerated message for OBS integration:
This bug (906831) was mentioned in
https://build.opensuse.org/request/show/263130 12.3 / flac
Comment 8 Takashi Iwai 2014-11-26 21:17:26 UTC
The fixed package are submitted to SLE10, SLE11, SLE12, openSUSE 12.3, 13.1 and 13.2.
Comment 10 Takashi Iwai 2014-11-28 09:08:40 UTC
Done.
Comment 12 Bernhard Wiedemann 2014-11-28 10:00:30 UTC
This is an autogenerated message for OBS integration:
This bug (906831) was mentioned in
https://build.opensuse.org/request/show/263297 13.2 / flac
https://build.opensuse.org/request/show/263298 12.3 / flac
https://build.opensuse.org/request/show/263299 13.1 / flac
Comment 13 Swamp Workflow Management 2014-11-28 12:04:07 UTC
An update workflow for this issue was started.
This issue was rated as low.
Please submit fixed packages until 2014-12-26.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/59824
Comment 15 Swamp Workflow Management 2014-12-06 06:04:49 UTC
SUSE-SU-2014:1577-1: An update that fixes two vulnerabilities is now available.

Category: security (low)
Bug References: 906831,907016
CVE References: CVE-2014-8962,CVE-2014-9028
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    flac-1.2.1-68.17.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    flac-1.2.1-68.17.1
SUSE Linux Enterprise Server 11 SP3 (src):    flac-1.2.1-68.17.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    flac-1.2.1-68.17.1
Comment 16 Swamp Workflow Management 2014-12-08 16:05:02 UTC
openSUSE-SU-2014:1588-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 906831,907016
CVE References: CVE-2014-8962,CVE-2014-9028
Sources used:
openSUSE 13.2 (src):    flac-1.3.0-4.4.1
openSUSE 13.1 (src):    flac-1.3.0-2.4.1
openSUSE 12.3 (src):    flac-1.2.1_git201212051942-3.4.1
Comment 17 Swamp Workflow Management 2014-12-18 14:04:56 UTC
SUSE-SU-2014:1663-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 906831,907016
CVE References: CVE-2014-8962,CVE-2014-9028
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    flac-1.3.0-6.1
SUSE Linux Enterprise Server 12 (src):    flac-1.3.0-6.1
SUSE Linux Enterprise Desktop 12 (src):    flac-1.3.0-6.1