Your submission was sent successfully! Close

CVE-2017-8372

Published: 01 May 2017

The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted audio file.

From the Ubuntu security team

Agostino Sarubbo discovered that libmad incorrectly handled certain audio files. An attacker could possibly use this issue to cause a denial of service or possibly other unspecified impact.

Priority

Low

CVSS 3 base score: 4.7

Status

Package Release Status
libmad
Launchpad, Ubuntu, Debian
Upstream
Released (0.15.1b-8+deb9u1)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (0.15.1b-9ubuntu18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (0.15.1b-9ubuntu16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (0.15.1b-9ubuntu14.04.1)