Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 634450 (CVE-2017-15370, CVE-2017-15371, CVE-2017-15372) - <media-sound/sox-14.4.2-r1: Crafted Input Leads to Denial of Service (CVE-2017-{15370,15371,15372})
Summary: <media-sound/sox-14.4.2-r1: Crafted Input Leads to Denial of Service (CVE-201...
Status: RESOLVED FIXED
Alias: CVE-2017-15370, CVE-2017-15371, CVE-2017-15372
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on: CVE-2017-15642
Blocks:
  Show dependency tree
 
Reported: 2017-10-16 15:07 UTC by Aleksandr Wagner (Kivak)
Modified: 2018-10-06 17:01 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Aleksandr Wagner (Kivak) 2017-10-16 15:07:08 UTC
CVE-2017-15372 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15372):

There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. 

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1500553

CVE-2017-15371 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15371):

There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. 

References:

https://bugzilla.redhat.com/show_bug.cgi?id=1500570
Comment 1 Larry the Git Cow gentoo-dev 2018-06-11 00:04:40 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ab144c7631ebe685ffec603e48824403fcd00cdd

commit ab144c7631ebe685ffec603e48824403fcd00cdd
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2018-06-10 23:45:11 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2018-06-11 00:04:20 +0000

    media-sound/sox: A truckload of security
    
    Kindly provided by Debian packaging...
    
    Bug: https://bugs.gentoo.org/627570
    Bug: https://bugs.gentoo.org/626702
    Bug: https://bugs.gentoo.org/634814
    Bug: https://bugs.gentoo.org/634450
    Package-Manager: Portage-2.3.40, Repoman-2.3.9

 .../sox/files/sox-14.4.2-CVE-2017-11332.patch      | 25 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-11333.patch      | 43 ++++++++++
 .../sox/files/sox-14.4.2-CVE-2017-11358.patch      | 26 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-11359.patch      | 27 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-15370.patch      | 25 ++++++
 .../sox/files/sox-14.4.2-CVE-2017-15371.patch      | 37 +++++++++
 .../sox/files/sox-14.4.2-CVE-2017-15372.patch      | 97 ++++++++++++++++++++++
 .../sox/files/sox-14.4.2-CVE-2017-15642.patch      | 28 +++++++
 .../sox/files/sox-14.4.2-CVE-2017-18189.patch      | 30 +++++++
 .../sox-14.4.2-wavpack-chk-errors-on-init.patch    | 35 ++++++++
 media-sound/sox/sox-14.4.2-r1.ebuild               | 13 +++
 11 files changed, 386 insertions(+)
Comment 2 Andreas Sturmlechner gentoo-dev 2018-09-14 19:54:24 UTC
sound is done here, anyway...
Comment 3 Yury German Gentoo Infrastructure gentoo-dev Security 2018-09-30 21:40:03 UTC
Arches and Maintainer(s). Thank you for your work.

GLSA Vote: Yes
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2018-10-06 17:01:51 UTC
This issue was resolved and addressed in
 GLSA 201810-02 at https://security.gentoo.org/glsa/201810-02
by GLSA coordinator Aaron Bauman (b-man).