Candidate: CVE-2017-8374 PublicDate: 2017-05-01 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8374 https://blogs.gentoo.org/ago/2017/04/30/libmad-heap-based-buffer-overflow-in-mad_bit_skip-bit-c/ Description: The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file. Ubuntu-Description: Agostino Sarubbo discovered that libmad incorrectly handled certain audio files. An attacker could possibly use this issue to cause a denial of service or possibly other unspecified impact. Notes: Bugs: Priority: low Discovered-by: Agostino Sarubbo Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_libmad: upstream_libmad: released (0.15.1b-8+deb9u1) precise_libmad: ignored (reached end-of-life) precise/esm_libmad: DNE (precise was needs-triage) trusty_libmad: released (0.15.1b-9ubuntu14.04.1) trusty/esm_libmad: released (0.15.1b-9ubuntu14.04.1) vivid/stable-phone-overlay_libmad: DNE vivid/ubuntu-core_libmad: DNE xenial_libmad: released (0.15.1b-9ubuntu16.04.1) yakkety_libmad: ignored (reached end-of-life) zesty_libmad: ignored (reached end-of-life) artful_libmad: ignored (reached end-of-life) bionic_libmad: released (0.15.1b-9ubuntu18.04.1) cosmic_libmad: released (0.15.1b-9ubuntu18.10.1) disco_libmad: not-affected (0.15.1b-9ubuntu18.10.1) devel_libmad: not-affected (0.15.1b-9ubuntu18.10.1)