{"id":"openSUSE-SU-2018:0544-1","summary":"Security update for lame","details":"This update for lame fixes the following issues:\n\nLame was updated to version 3.100:\n\n  * Improved detection of MPEG audio data in RIFF WAVE files.\n     sf#3545112 Invalid sampling detection\n  * New switch --gain \u003cdecibel\u003e, range -20.0 to +12.0, a more\n    convenient way to apply Gain adjustment in decibels, \n    than the use of --scale \u003cfactor\u003e.\n  * Fix for sf#3558466 Bug in path handling\n  * Fix for sf#3567844 problem with Tag genre\n  * Fix for sf#3565659 no progress indication with pipe input\n  * Fix for sf#3544957 scale (empty) silent encode without warning\n  * Fix for sf#3580176 environment variable LAMEOPT doesn't\n    work anymore\n  * Fix for sf#3608583 input file name displayed with wrong\n    character encoding (on windows console with CP_UTF8)\n  * Fix dereference NULL and Buffer not NULL terminated issues.\n    (CVE-2017-15019 bsc#1082317 CVE-2017-13712 bsc#1082399 CVE-2015-9100 bsc#1082401)\n  * Fix dereference of a null pointer possible in loop.\n  * Make sure functions with SSE instructions maintain their own\n    properly aligned stack. Thanks to Fabian Greffrath\n  * Multiple Stack and Heap Corruptions from Malicious File.\n    (CVE-2017-9872 bsc#1082391 CVE-2017-9871 bsc#1082392 CVE-2017-9870 bsc#1082393\n     CVE-2017-9869 bsc#1082395 CVE-2017-9411 bsc#1082397 CVE-2015-9101 bsc#1082400)\n  * CVE-2017-11720: Fix a division by zero vulnerability. (bsc#1082311)\n  * CVE-2017-9410: Fix fill_buffer_resample function in\n    libmp3lame/util.c heap-based buffer over-read and ap (bsc#1082333)\n  * CVE-2017-9411: Fix fill_buffer_resample function in\n    libmp3lame/util.c invalid memory read and application crash (bsc#1082397)\n  * CVE-2017-9412: FIx unpack_read_samples function in \n    frontend/get_audio.c invalid memory read and application crash (bsc#1082340)\n  * Fix clip detect scale suggestion unaware of scale input value\n  * HIP decoder bug fixed: decoding mixed blocks of lower sample\n    frequency Layer3 data resulted in internal buffer overflow.\n  * Add lame_encode_buffer_interleaved_int()\n\n","modified":"2026-03-11T07:32:00.048551Z","published":"2018-02-26T07:35:52Z","related":["CVE-2015-9100","CVE-2015-9101","CVE-2017-11720","CVE-2017-13712","CVE-2017-15019","CVE-2017-9410","CVE-2017-9411","CVE-2017-9412","CVE-2017-9869","CVE-2017-9870","CVE-2017-9871","CVE-2017-9872"],"upstream":["CVE-2015-9100","CVE-2015-9101","CVE-2017-11720","CVE-2017-13712","CVE-2017-15019","CVE-2017-9410","CVE-2017-9411","CVE-2017-9412","CVE-2017-9869","CVE-2017-9870","CVE-2017-9871","CVE-2017-9872"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KH623JZ3J2KZAJL44XIFV3PAHON2NVKG/#KH623JZ3J2KZAJL44XIFV3PAHON2NVKG"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082311"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082317"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082333"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082391"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082392"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082393"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082395"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082397"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082399"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082401"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-9100"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-9101"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-11720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-15019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9410"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-9872"}],"affected":[{"package":{"name":"lame","ecosystem":"SUSE:Package Hub 12 SP2","purl":"pkg:rpm/suse/lame&distro=SUSE%20Package%20Hub%2012%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.100-6.1"}]}],"ecosystem_specific":{"binaries":[{"lame":"3.100-6.1","libmp3lame-devel":"3.100-6.1","libmp3lame0":"3.100-6.1","lame-doc":"3.100-6.1","lame-mp3rtp":"3.100-6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2018:0544-1.json"}}],"schema_version":"1.7.5"}