Bug 1058436 (CVE-2017-14412) - VUL-0: CVE-2017-14412: mp3gain: An invalid memory write was discovered in copy_mp in interface.c in mpglibDBL,as used in MP3Gain version 1.5.2. The vulnerability causes a denial of service(segmentation fault and application crash) or possibly unsp
Summary: VUL-0: CVE-2017-14412: mp3gain: An invalid memory write was discovered in cop...
Status: RESOLVED WONTFIX
Alias: CVE-2017-14412
Product: openSUSE Distribution
Classification: openSUSE
Component: Other (show other bugs)
Version: Leap 42.2
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Luigi Baldoni
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-09-13 06:44 UTC by Marcus Meissner
Modified: 2018-02-10 18:00 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-09-13 06:44:56 UTC
CVE-2017-14412

An invalid memory write was discovered in copy_mp in interface.c in mpglibDBL,
as used in MP3Gain version 1.5.2. The vulnerability causes a denial of service
(segmentation fault and application crash) or possibly unspecified other impact.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14412
https://blogs.gentoo.org/ago/2017/09/08/mp3gain-invalid-memory-write-in-copy_mp-mpglibdblinterface-c/
Comment 1 Luigi Baldoni 2017-09-13 09:25:06 UTC
No longer supported upstream, not worth trying to fix it independently.
Filed (dr#525071).
Comment 2 Swamp Workflow Management 2018-02-10 18:00:06 UTC
This is an autogenerated message for OBS integration:
This bug (1058436) was mentioned in
https://build.opensuse.org/request/show/575251 Factory / mp3gain