openSUSE-SU-2018:0544-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:0544-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2018:0544-1
Related
Published
2018-02-26T07:35:52Z
Modified
2018-02-26T07:35:52Z
Summary
Security update for lame
Details

This update for lame fixes the following issues:

Lame was updated to version 3.100:

  • Improved detection of MPEG audio data in RIFF WAVE files. sf#3545112 Invalid sampling detection
  • New switch --gain <decibel>, range -20.0 to +12.0, a more convenient way to apply Gain adjustment in decibels, than the use of --scale <factor>.
  • Fix for sf#3558466 Bug in path handling
  • Fix for sf#3567844 problem with Tag genre
  • Fix for sf#3565659 no progress indication with pipe input
  • Fix for sf#3544957 scale (empty) silent encode without warning
  • Fix for sf#3580176 environment variable LAMEOPT doesn't work anymore
  • Fix for sf#3608583 input file name displayed with wrong character encoding (on windows console with CP_UTF8)
  • Fix dereference NULL and Buffer not NULL terminated issues. (CVE-2017-15019 bsc#1082317 CVE-2017-13712 bsc#1082399 CVE-2015-9100 bsc#1082401)
  • Fix dereference of a null pointer possible in loop.
  • Make sure functions with SSE instructions maintain their own properly aligned stack. Thanks to Fabian Greffrath
  • Multiple Stack and Heap Corruptions from Malicious File. (CVE-2017-9872 bsc#1082391 CVE-2017-9871 bsc#1082392 CVE-2017-9870 bsc#1082393 CVE-2017-9869 bsc#1082395 CVE-2017-9411 bsc#1082397 CVE-2015-9101 bsc#1082400)
  • CVE-2017-11720: Fix a division by zero vulnerability. (bsc#1082311)
  • CVE-2017-9410: Fix fillbufferresample function in libmp3lame/util.c heap-based buffer over-read and ap (bsc#1082333)
  • CVE-2017-9411: Fix fillbufferresample function in libmp3lame/util.c invalid memory read and application crash (bsc#1082397)
  • CVE-2017-9412: FIx unpackreadsamples function in frontend/get_audio.c invalid memory read and application crash (bsc#1082340)
  • Fix clip detect scale suggestion unaware of scale input value
  • HIP decoder bug fixed: decoding mixed blocks of lower sample frequency Layer3 data resulted in internal buffer overflow.
  • Add lameencodebufferinterleavedint()
References

Affected packages

SUSE:Package Hub 12 SP2 / lame

Package

Name
lame
Purl
pkg:rpm/suse/lame&distro=SUSE%20Package%20Hub%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.100-6.1

Ecosystem specific

{
    "binaries": [
        {
            "lame-doc": "3.100-6.1",
            "lame-mp3rtp": "3.100-6.1",
            "lame": "3.100-6.1",
            "libmp3lame-devel": "3.100-6.1",
            "libmp3lame0": "3.100-6.1"
        }
    ]
}