Bug 1037255 (CVE-2017-8419) - VUL-1: CVE-2017-8419: lame: denial of service (stack-based buffer overflow or heap-based buffer overflow) via a crafted file
Summary: VUL-1: CVE-2017-8419: lame: denial of service (stack-based buffer overflow or...
Status: RESOLVED UPSTREAM
Alias: CVE-2017-8419
Product: openSUSE.org
Classification: openSUSE
Component: 3rd party software (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.2
: P4 - Low : Normal (vote)
Target Milestone: ---
Assignee: E-mail List
QA Contact: E-mail List
URL: https://smash.suse.de/issue/184690/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-02 16:38 UTC by Mikhail Kasimov
Modified: 2018-02-21 06:40 UTC (History)
15 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
CVE-2017-8419_reproducer (50.14 KB, audio/x-wav)
2017-05-02 16:38 UTC, Mikhail Kasimov
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Mikhail Kasimov 2017-05-02 16:38:18 UTC
Created attachment 723519 [details]
CVE-2017-8419_reproducer

Ref: https://nvd.nist.gov/vuln/detail/CVE-2017-8419
====================================================
Description

LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of num_channels.
====================================================

Hyperlink

[1] https://sourceforge.net/p/lame/bugs/458/

[2] Reproducer: https://sourceforge.net/p/lame/bugs/458/attachment/lame_stack_corruption_poc.wav


(open-)SUSE: https://software.opensuse.org/package/lame

3.99.5 (TW, 42.{1,2}, hardware:sdr repo, multimedia:libs repo, and multimedia:musescore2 repo for TW only)
Comment 1 Andreas Stieger 2017-05-02 18:32:46 UTC
Not a distribution package, moving.

multimedia:libs/lame does not have an explicit maintainer set, cc'ing project maintainers.
Comment 2 Marcus Meissner 2018-02-21 06:40:21 UTC
we now have 3.100 in factory and leap.