Improper input validation in libmad - CVE-2017-8372
Published: May 8, 2018
Vulnerability identifier: #VU12403
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8372
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attackert o casue DoS condition on the target system.
The weakness exists in the mad_layer_III function in layer3.c due to assertion failure if NDEBUG is omitted. A remote attacker can submit a specially crafted audio file, trick the victim into opening it and cause the service to crash.
The weakness exists in the mad_layer_III function in layer3.c due to assertion failure if NDEBUG is omitted. A remote attacker can submit a specially crafted audio file, trick the victim into opening it and cause the service to crash.
Affected software
libmad
Debian Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
libmad (Alpine package)
libmad-debugsource
libmad-devel
libmad0
libmad0-debuginfo
libmad0-32bit
libmad0-32bit-debuginfo
Debian Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
libmad (Alpine package)
libmad-debugsource
libmad-devel
libmad0
libmad0-debuginfo
libmad0-32bit
libmad0-32bit-debuginfo
How to mitigate CVE-2017-8372
Install update from vendor's website.
libmad (Alpine package) - addressed in versions 0.15.1b-r8, 0.15.1b-r9
libmad-debugsource - update to 0.15.1b-150000.5.3.1
libmad-devel - update to 0.15.1b-150000.5.3.1
libmad0 - update to 0.15.1b-150000.5.3.1
libmad0-debuginfo - update to 0.15.1b-150000.5.3.1
libmad0-32bit - update to 0.15.1b-150000.5.3.1
libmad0-32bit-debuginfo - update to 0.15.1b-150000.5.3.1
libmad-debugsource - update to 0.15.1b-150000.5.3.1
libmad-devel - update to 0.15.1b-150000.5.3.1
libmad0 - update to 0.15.1b-150000.5.3.1
libmad0-debuginfo - update to 0.15.1b-150000.5.3.1
libmad0-32bit - update to 0.15.1b-150000.5.3.1
libmad0-32bit-debuginfo - update to 0.15.1b-150000.5.3.1