Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-15953 & CVE-2017-15954: heap-based buffer overflow and crash when processing a malformed CUE file. #1

Closed
hessu opened this issue Nov 13, 2017 · 0 comments
Assignees
Labels

Comments

@hessu
Copy link
Owner

hessu commented Nov 13, 2017

bchunk 1.2.0 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE file.

Fix committed in 6a053c1 provided by Yegor Timoshenko. Fixed in version 1.2.2.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15953
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15954
https://www.debian.org/security/2017/dsa-4026

@hessu hessu added the security label Nov 13, 2017
@hessu hessu self-assigned this Nov 13, 2017
@hessu hessu closed this as completed Nov 13, 2017
@hessu hessu changed the title CVE-2017-15953: heap-based buffer overflow and crash when processing a malformed CUE file. CVE-2017-15953 & CVE-2017-15954: heap-based buffer overflow and crash when processing a malformed CUE file. Nov 13, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant