Bug 1058450 (CVE-2017-14408) - VUL-0: CVE-2017-14408: mp3gain: A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL,as used in MP3Gain version 1.5.2. The vulnerability causes an application crash,which leads to remote denial of service.
Summary: VUL-0: CVE-2017-14408: mp3gain: A stack-based buffer over-read was discovered...
Status: RESOLVED WONTFIX
Alias: CVE-2017-14408
Product: openSUSE Distribution
Classification: openSUSE
Component: Other (show other bugs)
Version: Leap 42.2
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Luigi Baldoni
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-09-13 07:38 UTC by Marcus Meissner
Modified: 2018-02-10 18:00 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-09-13 07:38:23 UTC
CVE-2017-14408

A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL,
as used in MP3Gain version 1.5.2. The vulnerability causes an application crash,
which leads to remote denial of service.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14408
https://blogs.gentoo.org/ago/2017/09/08/mp3gain-stack-based-buffer-overflow-in-dct36-mpglibdbllayer3-c/
Comment 1 Luigi Baldoni 2017-09-13 09:26:05 UTC
No longer supported upstream, not worth trying to fix it independently.
Filed (dr#525071).
Comment 2 Swamp Workflow Management 2018-02-10 18:00:23 UTC
This is an autogenerated message for OBS integration:
This bug (1058450) was mentioned in
https://build.opensuse.org/request/show/575251 Factory / mp3gain