Описание
Security update for libmad
This update for libmad fixes the following issues:
- CVE-2017-8373: Fixed heap-based buffer overflow in mad_layer_III (bsc#1036968).
- CVE-2017-8372: Fixed assertion failure in layer3.c (bsc#1036969).
Список пакетов
SUSE Enterprise Storage 6
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Enterprise Storage 7
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP4
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server 15 SP1-BCL
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server 15 SP1-LTSS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server 15 SP2-BCL
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server 15-LTSS
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server for SAP Applications 15
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Manager Proxy 4.1
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Manager Retail Branch Server 4.1
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
SUSE Manager Server 4.1
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
openSUSE Leap 15.3
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
libmad0-32bit-0.15.1b-150000.5.3.1
openSUSE Leap 15.4
libmad-devel-0.15.1b-150000.5.3.1
libmad0-0.15.1b-150000.5.3.1
libmad0-32bit-0.15.1b-150000.5.3.1
Ссылки
- Link for SUSE-SU-2022:3782-1
- E-Mail link for SUSE-SU-2022:3782-1
- SUSE Security Ratings
- SUSE Bug 1036968
- SUSE Bug 1036969
- SUSE CVE CVE-2017-8372 page
- SUSE CVE CVE-2017-8373 page
Описание
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted audio file.
Затронутые продукты
SUSE Enterprise Storage 6:libmad-devel-0.15.1b-150000.5.3.1
SUSE Enterprise Storage 6:libmad0-0.15.1b-150000.5.3.1
SUSE Enterprise Storage 7:libmad-devel-0.15.1b-150000.5.3.1
SUSE Enterprise Storage 7:libmad0-0.15.1b-150000.5.3.1
Ссылки
- CVE-2017-8372
- SUSE Bug 1036969
Описание
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
Затронутые продукты
SUSE Enterprise Storage 6:libmad-devel-0.15.1b-150000.5.3.1
SUSE Enterprise Storage 6:libmad0-0.15.1b-150000.5.3.1
SUSE Enterprise Storage 7:libmad-devel-0.15.1b-150000.5.3.1
SUSE Enterprise Storage 7:libmad0-0.15.1b-150000.5.3.1
Ссылки
- CVE-2017-8373
- SUSE Bug 1036968