Debian Security Advisory
DSA-4192-1 libmad -- security update
- Date Reported:
- 04 May 2018
- Affected Packages:
- libmad
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-8372, CVE-2017-8373, CVE-2017-8374.
- More information:
-
Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.
For the oldstable distribution (jessie), these problems have been fixed in version 0.15.1b-8+deb8u1.
For the stable distribution (stretch), these problems have been fixed in version 0.15.1b-8+deb9u1.
We recommend that you upgrade your libmad packages.
For the detailed security status of libmad please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libmad