Your submission was sent successfully! Close

CVE-2017-8372

Published: 1 May 2017

The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted audio file.

From the Ubuntu security team

Agostino Sarubbo discovered that libmad incorrectly handled certain audio files. An attacker could possibly use this issue to cause a denial of service or possibly other unspecified impact.

Priority

Low

CVSS 3 base score: 4.7

Status

Package Release Status
libmad
Launchpad, Ubuntu, Debian
artful Ignored
(reached end-of-life)
bionic
Released (0.15.1b-9ubuntu18.04.1)
cosmic
Released (0.15.1b-9ubuntu18.10.1)
disco Not vulnerable
(0.15.1b-9ubuntu18.10.1)
precise Does not exist
(precise was needs-triage)
trusty
Released (0.15.1b-9ubuntu14.04.1)
upstream
Released (0.15.1b-8+deb9u1)
xenial
Released (0.15.1b-9ubuntu16.04.1)
yakkety Ignored
(reached end-of-life)
zesty Ignored
(reached end-of-life)