Logo
componentlibmad
Name
libmad
Version
0.15.1b
Type
library
Description
-
Licenses
GPL-2.0+
PURL
-
CPE
-

Other Versions#


Project
Branch
Version
master
0.15.1b

Patches#


#
Title
Author
Resolve
1
Patch #1
Unknown
2
Patch #2
Fabrice Fontaine <fontaine.fabrice@gmail.com>
3
Patch #3
Dario Binacchi <dario.binacchi@amarulasolutions.com>
4
Check the size of the main data
Kurt Roeckx <kurt@roeckx.be>
CVE-2017-8372
CVE-2017-8373
5
Check the size before reading with mad_bit_read
Kurt Roeckx <kurt@roeckx.be>
CVE-2017-8374

Vulnerabilities#


Name
Analysis
Description
Patched
The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
Patched
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
Patched
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted audio file.