Bug ID 1058452
Summary VUL-0: CVE-2017-14406: mp3gain: A NULL pointer dereference was discovered in sync_buffer in interface.c inmpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes asegmentation fault and application crash, which leads to remote denial
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee aloisio@gmx.com
Reporter meissner@suse.com
QA Contact qa-bugs@suse.de
Found By Security Response Team
Blocker ---

CVE-2017-14406

A NULL pointer dereference was discovered in sync_buffer in interface.c in
mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a
segmentation fault and application crash, which leads to remote denial of
service.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14406
https://blogs.gentoo.org/ago/2017/09/08/mp3gain-null-pointer-dereference-in-sync_buffer-mpglibdblinterface-c/


You are receiving this mail because: