Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 635602 (CVE-2017-9129, CVE-2017-9130) - <media-libs/faac-1.29.9.2: multiple vulnerabilities
Summary: <media-libs/faac-1.29.9.2: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2017-9129, CVE-2017-9130
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-10-27 16:44 UTC by GLSAMaker/CVETool Bot
Modified: 2018-11-25 01:21 UTC (History)
1 user (show)

See Also:
Package list:
media-libs/faac-1.29.9.2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-10-27 16:44:14 UTC
CVE-2017-9130 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9130):
  The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder
  (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid
  memory read and application crash) via a crafted wav file.

CVE-2017-9129 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9129):
  The wav_open_read function in frontend/input.c in Freeware Advanced Audio
  Coder (FAAC) 1.28 allows remote attackers to cause a denial of service
  (large loop) via a crafted wav file.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-10-27 16:45:13 UTC
@Maintainers could you please confirm if 1.28-r4 is affected?

Thank you.
Comment 2 Pacho Ramos gentoo-dev 2018-05-09 12:39:09 UTC
probably 1.29.9.2 will fix this
Comment 3 Frank Krömmelbein 2018-08-16 09:23:44 UTC
It looks like the fixes are definitely included since version 1.29 was released in july last year(!), see here:
https://sourceforge.net/p/faac/bugs/208/

And it seems that our current stable version IS vulnerable for at least CVE-2017-9130. I can apply the patch to fix this issue against faac-1.28-r4 source.
https://sourceforge.net/p/faac/bugs/_discuss/thread/0940294d/b003/attachment/faac_CVE-2017-9130.patch

I would suggest as soon as possible to stabilize latest version 1.29.9.2, I use this version for some time now.
Comment 4 Frank Krömmelbein 2018-08-31 22:24:32 UTC
PING!
2 more weeks have passed, but nothing has happened here.
Comment 5 Andreas Sturmlechner gentoo-dev 2018-09-14 18:55:45 UTC
oh well...
Comment 6 Matt Turner gentoo-dev 2018-09-17 23:16:29 UTC
Don't cc arches without a package list.
Comment 7 Matt Turner gentoo-dev 2018-09-18 17:16:13 UTC
ppc/ppc64 stable
Comment 8 Sergei Trofimovich (RETIRED) gentoo-dev 2018-09-19 08:56:59 UTC
ia64 stable
Comment 9 Rolf Eike Beer archtester 2018-09-19 16:18:38 UTC
sparc done.
Comment 10 Thomas Deutschmann (RETIRED) gentoo-dev 2018-09-19 17:35:57 UTC
x86 stable
Comment 11 Agostino Sarubbo gentoo-dev 2018-09-21 07:42:18 UTC
amd64 stable
Comment 12 Markus Meier gentoo-dev 2018-09-24 18:15:20 UTC
arm stable
Comment 13 Tobias Klausmann (RETIRED) gentoo-dev 2018-10-02 10:59:15 UTC
Stable on alpha.
Comment 14 Larry the Git Cow gentoo-dev 2018-10-02 12:11:52 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ed8e89fcf98331b1c04751d93284b8f9b0884b35

commit ed8e89fcf98331b1c04751d93284b8f9b0884b35
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2018-10-02 12:04:16 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2018-10-02 12:11:17 +0000

    media-libs/faac: Security cleanup
    
    Bug: https://bugs.gentoo.org/635602
    Package-Manager: Portage-2.3.50, Repoman-2.3.10
    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>

 media-libs/faac/Manifest                           |   2 -
 media-libs/faac/faac-1.28-r4.ebuild                |  59 ---------
 media-libs/faac/faac-1.29.8.3.ebuild               |  45 -------
 media-libs/faac/files/faac-1.28-altivec.patch      |  40 ------
 .../faac/files/faac-1.28-external-libmp4v2.patch   |  47 -------
 media-libs/faac/files/faac-1.28-inttypes.patch     |  41 ------
 .../files/faac-1.28-libmp4v2_r479_compat.patch     | 138 ---------------------
 7 files changed, 372 deletions(-)