Heap-based buffer overflow in libmad - CVE-2017-8373
Published: May 5, 2018 / Updated: May 8, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the mad_layer_III function in layer3.c due to heap-based buffer overflow. A remote attacker can submit a specially crafted audio file, trick the victim into opening it, trigger memory corruption and cause the service to crash.
Affected software
Debian Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
libmad (Alpine package)
libmad-debugsource
libmad-devel
libmad0
libmad0-debuginfo
libmad0-32bit
libmad0-32bit-debuginfo
How to mitigate CVE-2017-8373
libmad-debugsource - update to 0.15.1b-150000.5.3.1
libmad-devel - update to 0.15.1b-150000.5.3.1
libmad0 - update to 0.15.1b-150000.5.3.1
libmad0-debuginfo - update to 0.15.1b-150000.5.3.1
libmad0-32bit - update to 0.15.1b-150000.5.3.1
libmad0-32bit-debuginfo - update to 0.15.1b-150000.5.3.1