Bug ID 1058450
Summary VUL-0: CVE-2017-14408: mp3gain: A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL,as used in MP3Gain version 1.5.2. The vulnerability causes an application crash,which leads to remote denial of service.
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee aloisio@gmx.com
Reporter meissner@suse.com
QA Contact qa-bugs@suse.de
Found By Security Response Team
Blocker ---

CVE-2017-14408

A stack-based buffer over-read was discovered in dct36 in layer3.c in
mpglibDBL,
as used in MP3Gain version 1.5.2. The vulnerability causes an application
crash,
which leads to remote denial of service.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14408
https://blogs.gentoo.org/ago/2017/09/08/mp3gain-stack-based-buffer-overflow-in-dct36-mpglibdbllayer3-c/


You are receiving this mail because: