Oval Definition:
oval:org.opensuse.security:def:201712797
Revision Date
:
2019-09-27
Version
:
1
Title
:
CVE-2017-12797
Description
:
Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers to cause a denial of service via a crafted file, which triggers a heap-based buffer overflow.
Family
:
unix
Class
:
vulnerability
Status
:
Reference(s)
:
CVE-2017-12797
Platform(s)
:
openSUSE Leap 42.3
Product(s)
:
Definition Synopsis
openSUSE Leap 42.3 is installed
AND
Package Information
libmpg123-0-1.25.6-7 is installed
AND
libmpg123-0 is signed with openSUSE key
OR
libmpg123-0-32bit-1.25.6-7 is installed
AND
libmpg123-0-32bit is signed with openSUSE key
OR
libout123-0-1.25.6-7 is installed
AND
libout123-0 is signed with openSUSE key
OR
libout123-0-32bit-1.25.6-7 is installed
AND
libout123-0-32bit is signed with openSUSE key
OR
mpg123-1.25.6-7 is installed
AND
mpg123 is signed with openSUSE key
OR
mpg123-devel-1.25.6-7 is installed
AND
mpg123-devel is signed with openSUSE key
OR
mpg123-devel-32bit-1.25.6-7 is installed
AND
mpg123-devel-32bit is signed with openSUSE key
OR
mpg123-esound-1.25.6-7 is installed
AND
mpg123-esound is signed with openSUSE key
OR
mpg123-esound-32bit-1.25.6-7 is installed
AND
mpg123-esound-32bit is signed with openSUSE key
OR
mpg123-jack-1.25.6-7 is installed
AND
mpg123-jack is signed with openSUSE key
OR
mpg123-jack-32bit-1.25.6-7 is installed
AND
mpg123-jack-32bit is signed with openSUSE key
OR
mpg123-openal-1.25.6-7 is installed
AND
mpg123-openal is signed with openSUSE key
OR
mpg123-openal-32bit-1.25.6-7 is installed
AND
mpg123-openal-32bit is signed with openSUSE key
OR
mpg123-portaudio-1.25.6-7 is installed
AND
mpg123-portaudio is signed with openSUSE key
OR
mpg123-portaudio-32bit-1.25.6-7 is installed
AND
mpg123-portaudio-32bit is signed with openSUSE key
OR
mpg123-pulse-1.25.6-7 is installed
AND
mpg123-pulse is signed with openSUSE key
OR
mpg123-pulse-32bit-1.25.6-7 is installed
AND
mpg123-pulse-32bit is signed with openSUSE key
OR
mpg123-sdl-1.25.6-7 is installed
AND
mpg123-sdl is signed with openSUSE key
OR
mpg123-sdl-32bit-1.25.6-7 is installed
AND
mpg123-sdl-32bit is signed with openSUSE key
BACK