Candidate: CVE-2017-12087 PublicDate: 2018-04-24 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12087 https://bugs.launchpad.net/ubuntu/+source/shairport-sync/+bug/1729668 Description: An exploitable heap overflow vulnerability exists in the tinysvcmdns library version 2016-07-18. A specially crafted packet can make the library overwrite an arbitrary amount of data on the heap with attacker controlled values. An attacker needs send a dns packet to trigger this vulnerability. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882508 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_shairport-sync: upstream_shairport-sync: released (3.1.4-1) precise/esm_shairport-sync: DNE trusty_shairport-sync: DNE trusty/esm_shairport-sync: DNE xenial_shairport-sync: not-affected zesty_shairport-sync: ignored (reached end-of-life) artful_shairport-sync: ignored (reached end-of-life) bionic_shairport-sync: not-affected (3.1.4-1) cosmic_shairport-sync: not-affected (3.1.4-1) devel_shairport-sync: not-affected (3.1.4-1)