vendor:
libmad
by:
qflb.wu
6,5
CVSS
MEDIUM
Memory Corruption
416
CWE
Product Name: libmad
Affected Version From: 0.15.1b
Affected Version To: 0.15.1b
Patch Exists: YES
Related CWE: CVE-2017-11552
CPE: a:underbit_technologies:libmad:0.15.1b
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
libmad memory corruption vulnerability
The mad_decoder_run function in decoder.c in libmad 0.15.1b can cause a denial of service(memory corruption) via a crafted mp3 file. I found this bug when I test mpg321 0.3.2 which used the libmad library.
Mitigation:
Upgrade to the latest version of libmad library