Candidate: CVE-2017-9256 PublicDate: 2017-06-27 12:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9256 http://seclists.org/fulldisclosure/2017/Jun/32 Description: The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file. Ubuntu-Description: It was discovered that Freeware Advanced Audio Decoder 2 incorrectly handled certain mp4 files. A remote attacker could possibly use this issue to cause a denial of service. Notes: ratliff> reproducer errors out Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_faad2: upstream_faad2: released ((2.8.1-1)) precise/esm_faad2: DNE trusty_faad2: released (2.7-8+deb7u1build0.14.04.1) trusty/esm_faad2: DNE (trusty was released [2.7-8+deb7u1build0.14.04.1]) vivid/ubuntu-core_faad2: DNE xenial_faad2: released (2.8.0~cvs20150510-1ubuntu0.1) yakkety_faad2: ignored (reached end-of-life) zesty_faad2: ignored (reached end-of-life) artful_faad2: not-affected ((2.8.1-2)) bionic_faad2: not-affected ((2.8.1-2)) cosmic_faad2: not-affected ((2.8.1-2)) devel_faad2: not-affected ((2.8.1-2))