Heap-based buffer over-read in libmad - CVE-2017-8374

 

Heap-based buffer over-read in libmad - CVE-2017-8374

Published: May 5, 2018 / Updated: May 8, 2018


Vulnerability identifier: #VU12405
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8374
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target ystem.

The weakness exists in the mad_bit_skip function in bit.c due to heap-based buffer over-read. A remote attacker can submit a specially crafted audio file, trick the victim into opening it, trigger memory corruption and cause the service to crash.


Affected software

libmad
Debian Linux
libmad (Alpine package)

How to mitigate CVE-2017-8374

Install update from vendor's website.

libmad (Alpine package) - addressed in versions 0.15.1b-r8, 0.15.1b-r9

External References

Related Security Bulletins