Bug ID 1058448
Summary VUL-0: CVE-2017-14410: mp3gain: A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, asused in MP3Gain version 1.5.2. The vulnerability causes an application crash,which leads to remote denial of service.
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee aloisio@gmx.com
Reporter meissner@suse.com
QA Contact qa-bugs@suse.de
Found By Security Response Team
Blocker ---

CVE-2017-14410

A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as
used in MP3Gain version 1.5.2. The vulnerability causes an application crash,
which leads to remote denial of service.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14410
https://blogs.gentoo.org/ago/2017/09/08/mp3gain-global-buffer-overflow-in-iii_i_stereo-mpglibdbllayer3-c/


You are receiving this mail because: