Vulnerability Name:

CVE-2017-8374 (CCN-125513)

Assigned:2017-04-30
Published:2017-04-30
Updated:2018-05-20
Summary:The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-8374

Source: CCN
Type: Underbit Web site
Underbit: MAD (MPEG Audio Decoder)

Source: CCN
Type: agostino's blog, April 30, 2017
libmad: heap-based buffer overflow in mad_bit_skip (bit.c)

Source: MISC
Type: Exploit, Third Party Advisory, VDB Entry
https://blogs.gentoo.org/ago/2017/04/30/libmad-heap-based-buffer-overflow-in-mad_bit_skip-bit-c/

Source: XF
Type: UNKNOWN
underbit-cve20178374-dos(125513)

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20180518 [SECURITY] [DLA 1380-1] libmad security update

Source: DEBIAN
Type: UNKNOWN
DSA-4192

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-8374

Vulnerable Configuration:Configuration 1:
  • cpe:/a:underbit:mad_libmad:0.15.1b:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:underbit:mad_libmad:0.15.1b:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20178374
    V
    CVE-2017-8374
    2023-06-22
    oval:org.opensuse.security:def:7944
    P
    libmad-devel-0.15.1b-150000.5.3.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:781
    P
    Security update for unzip (Moderate)
    2022-09-26
    oval:org.opensuse.security:def:671
    P
    Security update for ldb, samba (Important)
    2022-08-03
    oval:org.opensuse.security:def:3323
    P
    perl-32bit-5.18.2-12.20.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94953
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1235
    P
    Security update for postgresql10 (Important)
    2022-05-31
    oval:org.opensuse.security:def:1363
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP3) (Important)
    2022-05-26
    oval:org.opensuse.security:def:100775
    P
    (Moderate)
    2022-03-24
    oval:org.opensuse.security:def:94062
    P
    (Moderate)
    2022-03-14
    oval:org.opensuse.security:def:112680
    P
    libmad-devel-0.15.1b-3.15 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:67815
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15) (Important)
    2021-12-14
    oval:org.opensuse.security:def:1591
    P
    Security update for the Linux Kernel (Important)
    2021-10-13
    oval:org.opensuse.security:def:106159
    P
    libmad-devel-0.15.1b-3.15 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71155
    P
    ceph-common-14.2.0.300+gacd2f2b9e1-1.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71268
    P
    libjbig-devel-2.1-1.31 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64568
    P
    Security update for xen (Important)
    2021-09-02
    oval:org.opensuse.security:def:1707
    P
    Security update for nodejs12 (Important)
    2021-08-30
    oval:org.opensuse.security:def:49448
    P
    Security update for nodejs10 (Moderate)
    2021-08-24
    oval:org.opensuse.security:def:47192
    P
    yast2-users-3.1.57-16.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47855
    P
    perl-YAML-LibYAML-0.38-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47521
    P
    update-alternatives-1.18.4-14.216 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47763
    P
    libplist3-1.12-20.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47328
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47302
    P
    krb5-appl-clients-1.0.3-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48191
    P
    libsmi-0.4.8-18.55 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47631
    P
    grub2-2.02-11.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47207
    P
    apache2-mod_perl-2.0.8-11.43 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48107
    P
    libevent-2_0-5-2.0.21-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47438
    P
    libz1-1.2.8-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47193
    P
    zoo-2.10-1020.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48349
    P
    xorg-x11-server-1.19.6-8.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48301
    P
    rzsz-0.12.21~rc-1001.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47893
    P
    strongswan-5.1.3-26.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47317
    P
    libXinerama1-1.1.3-3.54 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48318
    P
    sysstat-12.0.2-10.24.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48217
    P
    libvmtools0-10.3.10-4.12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47745
    P
    libmusicbrainz4-2.1.5-27.79 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47303
    P
    lftp-4.7.4-1.13 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48253
    P
    p7zip-9.20.1-7.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48003
    P
    evince-3.20.2-6.27.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47653
    P
    java-1_8_0-openjdk-1.8.0.181-27.26.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:1117
    P
    libpython3_6m1_0-3.6.13-3.78.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72515
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62796
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101202
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1007
    P
    gstreamer-plugins-base-1.16.2-2.12 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1473
    P
    Security update for gupnp (Important)
    2021-06-24
    oval:org.opensuse.security:def:48428
    P
    glib2-lang-2.48.2-10.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48363
    P
    alsa-1.0.27.2-11.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48420
    P
    fuse-2.9.3-5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48530
    P
    libopenssl-devel-1.0.2j-55.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48459
    P
    libMagickCore-6_Q16-1-6.8.8.1-33.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64481
    P
    Security update for giflib (Low)
    2021-04-28
    oval:org.opensuse.security:def:66742
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:69993
    P
    Security update for MozillaFirefox (Important)
    2021-03-02
    oval:org.opensuse.security:def:72281
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103567
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62562
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72399
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107441
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62680
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116999
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72171
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62452
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89912
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25036
    P
    Security update for sqlite3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25588
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49676
    P
    libmad-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24972
    P
    Security update for xrdp (Important)
    2020-12-01
    oval:org.opensuse.security:def:25734
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24961
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70098
    P
    libmad-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25535
    P
    Security update for audiofile (Low)
    2020-12-01
    oval:org.opensuse.security:def:26407
    P
    Security update for libmad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49622
    P
    firewall-applet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73315
    P
    shadow on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25690
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:25385
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25676
    P
    Security update for postgresql, postgresql96, postgresql10 and postgresql12 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25301
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26372
    P
    Recommended update for geotiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25244
    P
    Security update for log4j (Important)
    2020-12-01
    oval:org.opensuse.security:def:49394
    P
    colord-color-profiles on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49558
    P
    libmad-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66650
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25163
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:67915
    P
    libmad-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73433
    P
    libmad-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49504
    P
    bubblewrap on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201783740000000
    V
    CVE-2017-8374 on Ubuntu 18.04 LTS (bionic) - low.
    2017-05-01
    oval:com.ubuntu.xenial:def:201783740000000
    V
    CVE-2017-8374 on Ubuntu 16.04 LTS (xenial) - low.
    2017-05-01
    oval:com.ubuntu.disco:def:201783740000000
    V
    CVE-2017-8374 on Ubuntu 19.04 (disco) - low.
    2017-05-01
    oval:com.ubuntu.cosmic:def:201783740000000
    V
    CVE-2017-8374 on Ubuntu 18.10 (cosmic) - low.
    2017-04-30
    oval:com.ubuntu.artful:def:20178374000
    V
    CVE-2017-8374 on Ubuntu 17.10 (artful) - low.
    2017-04-30
    oval:com.ubuntu.trusty:def:20178374000
    V
    CVE-2017-8374 on Ubuntu 14.04 LTS (trusty) - low.
    2017-04-30
    oval:com.ubuntu.bionic:def:20178374000
    V
    CVE-2017-8374 on Ubuntu 18.04 LTS (bionic) - low.
    2017-04-30
    oval:com.ubuntu.xenial:def:20178374000
    V
    CVE-2017-8374 on Ubuntu 16.04 LTS (xenial) - low.
    2017-04-30
    oval:com.ubuntu.cosmic:def:20178374000
    V
    CVE-2017-8374 on Ubuntu 18.10 (cosmic) - low.
    2017-04-30
    oval:com.ubuntu.precise:def:20178374000
    V
    CVE-2017-8374 on Ubuntu 12.04 LTS (precise) - low.
    2017-04-30
    BACK
    underbit mad libmad 0.15.1b
    underbit mad libmad 0.15.1b