~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-9254

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-9254
2
 
PublicDate: 2017-06-27
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9254
5
 
 http://seclists.org/fulldisclosure/2017/Jun/32
6
 
Description:
7
 
 The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced
8
 
 Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of
9
 
 service (large loop and CPU consumption) via a crafted mp4 file.
10
 
Ubuntu-Description:
11
 
Notes:
12
 
 ratliff> reproducer errors out 
13
 
Bugs:
14
 
Priority: low
15
 
Discovered-by:
16
 
Assigned-to:
17
 
 
18
 
Patches_faad2:
19
 
upstream_faad2: released ((2.8.1-1))
20
 
precise/esm_faad2: DNE
21
 
trusty_faad2: released (2.7-8+deb7u1build0.14.04.1)
22
 
vivid/ubuntu-core_faad2: DNE
23
 
xenial_faad2: needs-triage
24
 
yakkety_faad2: ignored (reached end-of-life)
25
 
zesty_faad2: ignored (reached end-of-life)
26
 
artful_faad2: not-affected ((2.8.1-2))
27
 
bionic_faad2: not-affected ((2.8.1-2))
28
 
devel_faad2: not-affected ((2.8.1-2))