Bug#870406: [pkg-mad-maintainers] Bug#870406: Bug#870406: libmad: CVE-2017-11552

2018-01-07 Thread Kurt Roeckx
reassign 870406 mpg321 thanks On Sun, Jan 07, 2018 at 02:43:43PM +0100, Kurt Roeckx wrote: > I can reproduce this using mpg321, but not using madplay. Valgrind shows: ==4094== Invalid write of size 8 ==4094==at 0x10EFD0: read_header (mad.c:285) ==4094==by 0x579EA11: run_sync (decoder.c:39

Bug#870406: [pkg-mad-maintainers] Bug#870406: libmad: CVE-2017-11552

2018-01-07 Thread Kurt Roeckx
On Tue, Aug 01, 2017 at 07:24:56PM +0200, Salvatore Bonaccorso wrote: > > Hi, > > the following vulnerability was published for libmad. > > CVE-2017-11552[0]: > | The mad_decoder_run function in decoder.c in libmad 0.15.1b allows > | remote attackers to cause a denial of service (memory corrupti

Bug#870406: [pkg-mad-maintainers] Bug#870406: libmad: CVE-2017-11552

2017-08-01 Thread Salvatore Bonaccorso
Hi Kurt On Tue, Aug 01, 2017 at 07:48:01PM +0200, Kurt Roeckx wrote: > On Tue, Aug 01, 2017 at 07:24:56PM +0200, Salvatore Bonaccorso wrote: > > Source: libmad > > Version: 0.15.1b-7 > > Severity: important > > Tags: security upstream > > > > Hi, > > > > the following vulnerability was published

Bug#870406: [pkg-mad-maintainers] Bug#870406: libmad: CVE-2017-11552

2017-08-01 Thread Kurt Roeckx
On Tue, Aug 01, 2017 at 07:24:56PM +0200, Salvatore Bonaccorso wrote: > Source: libmad > Version: 0.15.1b-7 > Severity: important > Tags: security upstream > > Hi, > > the following vulnerability was published for libmad. > > CVE-2017-11552[0]: > | The mad_decoder_run function in decoder.c in li

Bug#870406: libmad: CVE-2017-11552

2017-08-01 Thread Salvatore Bonaccorso
Source: libmad Version: 0.15.1b-7 Severity: important Tags: security upstream Hi, the following vulnerability was published for libmad. CVE-2017-11552[0]: | The mad_decoder_run function in decoder.c in libmad 0.15.1b allows | remote attackers to cause a denial of service (memory corruption) via