Bug ID 1058447
Summary VUL-0: CVE-2017-14411: mp3gain: A stack-based buffer overflow was discovered in copy_mp in interface.c inmpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes anout-of-bounds write, which leads to remote denial of service or possib
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee aloisio@gmx.com
Reporter meissner@suse.com
QA Contact qa-bugs@suse.de
Found By Security Response Team
Blocker ---

CVE-2017-14411

A stack-based buffer overflow was discovered in copy_mp in interface.c in
mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an
out-of-bounds write, which leads to remote denial of service or possibly code
execution.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-14411
https://blogs.gentoo.org/ago/2017/09/08/mp3gain-stack-based-buffer-overflow-in-copy_mp-mpglibdblinterface-c/


You are receiving this mail because: