Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 634450 (CVE-2017-15370, CVE-2017-15371, CVE-2017-15372)

Summary: <media-sound/sox-14.4.2-r1: Crafted Input Leads to Denial of Service (CVE-2017-{15370,15371,15372})
Product: Gentoo Security Reporter: Aleksandr Wagner (Kivak) <alwag>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [glsa+ cve]
Package list:
Runtime testing required: ---
Bug Depends on: 634814    
Bug Blocks:    

Description Aleksandr Wagner (Kivak) 2017-10-16 15:07:08 UTC
CVE-2017-15372 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15372):

There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. 

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1500553

CVE-2017-15371 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15371):

There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. 

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1500570
Comment 1 Larry the Git Cow gentoo-dev 2018-06-11 00:04:40 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ab144c7631ebe685ffec603e48824403fcd00cdd

commit ab144c7631ebe685ffec603e48824403fcd00cdd
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2018-06-10 23:45:11 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2018-06-11 00:04:20 +0000

    media-sound/sox: A truckload of security
    
    Kindly provided by Debian packaging...
    
    Bug: https://bugs.gentoo.org/627570
    Bug: https://bugs.gentoo.org/626702
    Bug: https://bugs.gentoo.org/634814
    Bug: https://bugs.gentoo.org/634450
    Package-Manager: Portage-2.3.40, Repoman-2.3.9

 .../sox/files/sox-14.4.2-CVE-2017-11332.patch      | 25 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-11333.patch      | 43 ++++++++++
 .../sox/files/sox-14.4.2-CVE-2017-11358.patch      | 26 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-11359.patch      | 27 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-15370.patch      | 25 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-15371.patch      | 37 +++++++++
 .../sox/files/sox-14.4.2-CVE-2017-15372.patch      | 97 ++++++++++++++++++++++
 .../sox/files/sox-14.4.2-CVE-2017-15642.patch      | 28 +++++++
 .../sox/files/sox-14.4.2-CVE-2017-18189.patch      | 30 +++++++
 .../sox-14.4.2-wavpack-chk-errors-on-init.patch    | 35 ++++++++
 media-sound/sox/sox-14.4.2-r1.ebuild               | 13 +++
 11 files changed, 386 insertions(+)
Comment 2 Andreas Sturmlechner gentoo-dev 2018-09-14 19:54:24 UTC
sound is done here, anyway...
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2018-09-30 21:40:03 UTC
Arches and Maintainer(s). Thank you for your work.

GLSA Vote: Yes
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2018-10-06 17:01:51 UTC
This issue was resolved and addressed in
 GLSA 201810-02 at https://security.gentoo.org/glsa/201810-02
by GLSA coordinator Aaron Bauman (b-man).