USN-4780-1: LAME vulnerabilities
29 August 2022
Several security issues were fixed in LAME.
Releases
Packages
- lame - MP3 encoding library (frontend)
Details
It was discovered that LAME incorrectly handled certain audio files. A
remote attacker could possibly use this issue to cause a denial of service. Eight
vulnerabilities (CVE-2015-9099, CVE-2015-9100, CVE-2015-9101, CVE-2017-15018,
CVE-2017-11720, CVE-2017-8419, CVE-2017-9412, CVE-2017-15045) only affected Ubuntu 14.04
ESM, two vulnerabilities (CVE-2017-9410 and CVE-2017-9411) only affected Ubuntu
16.04 ESM, and one vulnerability (CVE-2017-15019) affected both Ubuntu 14.04
ESM and Ubuntu 16.04.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libmp3lame0
-
3.99.5+repack1-9ubuntu0.1~esm2
Available with Ubuntu Pro
-
lame
-
3.99.5+repack1-9ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 14.04
-
libmp3lame0
-
3.99.5+repack1-3ubuntu1+esm3
Available with Ubuntu Pro
-
lame
-
3.99.5+repack1-3ubuntu1+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.