Candidate: CVE-2017-8373 PublicDate: 2017-05-01 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8373 https://blogs.gentoo.org/ago/2017/04/30/libmad-heap-based-buffer-overflow-in-mad_layer_iii-layer3-c/ Description: The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file. Ubuntu-Description: Agostino Sarubbo discovered that libmad incorrectly handled certain audio files. An attacker could possibly use this issue to cause a denial of service or possibly other unspecified impact. Notes: Bugs: Priority: medium Discovered-by: Agostino Sarubbo Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_libmad: upstream_libmad: released (0.15.1b-8+deb9u1) precise_libmad: ignored (reached end-of-life) precise/esm_libmad: DNE (precise was needs-triage) trusty_libmad: released (0.15.1b-9ubuntu14.04.1) trusty/esm_libmad: released (0.15.1b-9ubuntu14.04.1) vivid/stable-phone-overlay_libmad: DNE vivid/ubuntu-core_libmad: DNE xenial_libmad: released (0.15.1b-9ubuntu16.04.1) yakkety_libmad: ignored (reached end-of-life) zesty_libmad: ignored (reached end-of-life) artful_libmad: ignored (reached end-of-life) bionic_libmad: released (0.15.1b-9ubuntu18.04.1) cosmic_libmad: released (0.15.1b-9ubuntu18.10.1) disco_libmad: not-affected (0.15.1b-9ubuntu18.10.1) devel_libmad: not-affected (0.15.1b-9ubuntu18.10.1)