Vulnerability Name:

CVE-2017-9412 (CCN-129628)

Assigned:2017-07-26
Published:2017-07-26
Updated:2017-08-12
Summary:The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
5.0 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:P/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
3.0 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-9412

Source: CCN
Type: SourceForge LAME Project
LAME

Source: CCN
Type: Full-Disclosure Mailing List, Wed, 26 Jul 2017 10:39:27 +0800 (GMT+08:00)
LAME multiple vulnerabilities

Source: MISC
Type: Exploit, Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jul/63

Source: XF
Type: UNKNOWN
lame-cve20179412-dos(129628)

Source: CCN
Type: Packet Storm Security [07-26-2017]
LAME 3.99.5 Denial Of Service

Source: EXPLOIT-DB
Type: UNKNOWN
42390

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2017-9412

Vulnerable Configuration:Configuration 1:
  • cpe:/a:lame_project:lame:3.99.5:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:lame_project:lame:3.99.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20179412
    V
    CVE-2017-9412
    2023-06-22
    oval:org.opensuse.security:def:7949
    P
    libmp3lame-devel-3.100-150000.3.2.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7618
    P
    libmp3lame0-3.100-150000.3.2.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:785
    P
    Security update for rust1.62 (Moderate)
    2022-09-28
    oval:org.opensuse.security:def:754
    P
    Security update for nodejs16 (Moderate)
    2022-09-12
    oval:org.opensuse.security:def:675
    P
    Security update for qpdf (Important)
    2022-08-04
    oval:org.opensuse.security:def:3033
    P
    clamav-0.101.3-1.19 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3328
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:1239
    P
    Security update for the Linux Kernel (Important)
    2022-06-24
    oval:org.opensuse.security:def:94663
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94958
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:159
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1367
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP3) (Important)
    2022-06-05
    oval:org.opensuse.security:def:93810
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:1595
    P
    Security update for the Linux Kernel (Important)
    2022-04-26
    oval:org.opensuse.security:def:1088
    P
    Security update for webkit2gtk3 (Important)
    2022-03-04
    oval:org.opensuse.security:def:94269
    P
    (Important)
    2022-02-18
    oval:org.opensuse.security:def:112532
    P
    lame-3.100-3.7 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:1711
    P
    Security update for nodejs12 (Important)
    2021-12-06
    oval:org.opensuse.security:def:69741
    P
    Security update for python-Pygments (Important)
    2021-10-20
    oval:org.opensuse.security:def:106021
    P
    lame-3.100-3.7 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:49452
    P
    Security update for nodejs14 (Important)
    2021-09-22
    oval:org.opensuse.security:def:71159
    P
    coreutils-8.29-2.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71272
    P
    libksba-devel-1.3.5-2.14 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64572
    P
    Security update for xerces-c (Important)
    2021-09-06
    oval:org.opensuse.security:def:1121
    P
    Security update for go1.16 (Moderate)
    2021-08-20
    oval:org.opensuse.security:def:1477
    P
    Security update for libsndfile (Critical)
    2021-08-17
    oval:org.opensuse.security:def:47332
    P
    libasan2-32bit-5.3.1+r233831-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47306
    P
    libIlmImf-Imf_2_1-21-2.1.0-4.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48195
    P
    libsoup-2_4-1-2.62.2-5.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47635
    P
    gstreamer-plugins-good-1.8.3-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47211
    P
    autofs-5.0.9-27.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48111
    P
    libfreebl3-3.45-58.31.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47442
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47197
    P
    accountsservice-0.6.42-14.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48353
    P
    yast2-core-3.3.1-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48305
    P
    shadow-4.2.1-34.20 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47897
    P
    sysconfig-0.84.0-13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47321
    P
    libXrender1-0.9.8-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48322
    P
    tboot-20190704_1.9.10-1.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48221
    P
    libvte9-0.28.2-19.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47749
    P
    libnetpbm11-10.66.3-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47307
    P
    libMagickCore-6_Q16-1-6.8.8.1-70.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48257
    P
    pam_ssh-2.0-1.39 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48007
    P
    flatpak-1.4.2-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47657
    P
    kernel-firmware-20180525-3.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47196
    P
    aaa_base-13.2+git20140911.61c1681-36.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47859
    P
    ppc64-diag-2.7.4-1.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47525
    P
    w3m-0.5.3.git20161120-160.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47767
    P
    libpolkit0-0.113-5.12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:100982
    P
    lame-3.100-1.33 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63479
    P
    lame-3.100-1.33 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2390
    P
    lame-3.100-1.33 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:107648
    P
    lame-3.100-1.33 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63425
    P
    lame-3.100-1.33 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2336
    P
    lame-3.100-1.33 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:1011
    P
    hunspell-1.6.2-3.3.7 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100935
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62177
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62800
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101206
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71918
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100779
    P
    apache-commons-httpclient-3.1-11.3.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72519
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:48424
    P
    gdm-3.10.0.1-52.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48534
    P
    libpng12-0-1.2.50-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48463
    P
    libXRes1-1.0.7-3.53 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48432
    P
    gnome-shell-3.20.4-70.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48367
    P
    apache-commons-httpclient-3.1-4.364 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64485
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:66746
    P
    Security update for ruby2.5 (Moderate)
    2021-04-20
    oval:org.opensuse.security:def:67819
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-03-17
    oval:org.opensuse.security:def:69997
    P
    Security update for postgresql12 (Moderate)
    2021-03-03
    oval:org.opensuse.security:def:69846
    P
    Security update for tcmu-runner (Important)
    2021-01-18
    oval:org.opensuse.security:def:66490
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:61843
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62684
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72285
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116747
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103571
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89916
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71584
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100523
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72403
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117003
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107189
    P
    libmp3lame0-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62456
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107445
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94066
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62566
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72175
    P
    libmp3lame-devel-3.100-1.33 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:73063
    P
    curl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25692
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73181
    P
    libmp3lame0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25387
    P
    Security update for shim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25678
    P
    Security update for kernel-firmware (Important)
    2020-12-01
    oval:org.opensuse.security:def:25303
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49398
    P
    eog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73319
    P
    spectre-meltdown-checker on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73437
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66398
    P
    glib2-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25246
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:70102
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49562
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49508
    P
    emacs-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25165
    P
    Security update for squid (Important)
    2020-12-01
    oval:org.opensuse.security:def:26374
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26409
    P
    Security update for lame (Important)
    2020-12-01
    oval:org.opensuse.security:def:66654
    P
    xorg-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25038
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:49680
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25590
    P
    Security update for dovecot22 (Important)
    2020-12-01
    oval:org.opensuse.security:def:49626
    P
    gcab on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24974
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25736
    P
    Security update for mozilla-nspr, mozilla-nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67919
    P
    libmp3lame-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24963
    P
    Security update for dnsmasq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49195
    P
    libmp3lame0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25537
    P
    Security update for gnuplot (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49141
    P
    libXdmcp-devel on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201794120000000
    V
    CVE-2017-9412 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-07-27
    oval:com.ubuntu.artful:def:20179412000
    V
    CVE-2017-9412 on Ubuntu 17.10 (artful) - medium.
    2017-07-27
    oval:com.ubuntu.xenial:def:20179412000
    V
    CVE-2017-9412 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-07-27
    oval:com.ubuntu.xenial:def:201794120000000
    V
    CVE-2017-9412 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-07-27
    oval:com.ubuntu.bionic:def:20179412000
    V
    CVE-2017-9412 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-07-27
    oval:com.ubuntu.disco:def:201794120000000
    V
    CVE-2017-9412 on Ubuntu 19.04 (disco) - medium.
    2017-07-27
    oval:com.ubuntu.cosmic:def:20179412000
    V
    CVE-2017-9412 on Ubuntu 18.10 (cosmic) - medium.
    2017-07-27
    oval:com.ubuntu.cosmic:def:201794120000000
    V
    CVE-2017-9412 on Ubuntu 18.10 (cosmic) - medium.
    2017-07-27
    oval:com.ubuntu.trusty:def:20179412000
    V
    CVE-2017-9412 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-07-27
    BACK
    lame_project lame 3.99.5
    lame_project lame 3.99.5