Candidate: CVE-2017-17446 PublicDate: 2017-12-06 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17446 https://bitbucket.org/mpyne/game-music-emu/issues/14/addresssanitizer-negative-size-param-size https://bugs.debian.org/883691 Description: The Mem_File_Reader::read_avail function in Data_Reader.cpp in the Game_Music_Emu library (aka game-music-emu) 0.6.1 does not ensure a non-negative size, which allows remote attackers to cause a denial of service (application crash) via a crafted file. Ubuntu-Description: It was discovered that game-music-emu mishandled certain crafted input. A local attacker could use this vulnerability to cause game-music-emu to crash. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883691 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_game-music-emu: upstream_game-music-emu: released (0.6.2-1) precise/esm_game-music-emu: DNE trusty_game-music-emu: ignored (out of standard support) trusty/esm_game-music-emu: released (0.5.5-2ubuntu0.14.04.1+esm1) xenial_game-music-emu: ignored (end of standard support, was needed) zesty_game-music-emu: ignored (reached end-of-life) artful_game-music-emu: ignored (reached end-of-life) bionic_game-music-emu: not-affected (0.6.2-1) cosmic_game-music-emu: not-affected (0.6.2-1) disco_game-music-emu: not-affected (0.6.2-1) eoan_game-music-emu: not-affected (0.6.2-1) focal_game-music-emu: not-affected (0.6.2-1) groovy_game-music-emu: not-affected (0.6.2-1) hirsute_game-music-emu: not-affected (0.6.2-1) impish_game-music-emu: not-affected (0.6.2-1) jammy_game-music-emu: not-affected (0.6.2-1) devel_game-music-emu: not-affected (0.6.2-1)