Bug 1167236 (CVE-2014-8962)

Summary: CVE-2014-8962 flac: Buffer read overflow when processing ID3V2 metadata
Product: [Other] Security Response Reporter: Vasyl Kaigorodov <vkaigoro>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: falonso, matthias, mlichvar, valtri
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: flac 1.3.1pre1 Doc Type: Bug Fix
Doc Text:
A buffer over-read flaw was found in the way flac processed certain ID3v2 metadata. An attacker could create a specially crafted FLAC audio file that could cause an application using the flac library to crash when the file was read.
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-04-01 11:20:48 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1169698, 1169699, 1169700, 1192670, 1192671, 1192672, 1192673    
Bug Blocks: 1167237    

Description Vasyl Kaigorodov 2014-11-24 09:28:40 UTC
Unspecified vulnerability was fixed in flac upstream repository [1]

There're currently no publicly availble details about this issue:
The commit above will be included in flac 1.3.1, which will be out early next week [2].

[1]: https://git.xiph.org/?p=flac.git;a=commitdiff;h=5b3033a2b355068c11fe637e14ac742d273f076e
[2]: http://lists.xiph.org/pipermail/flac-dev/2014-November/005185.html

Comment 3 Francisco Alonso 2014-12-02 09:00:53 UTC
Created mingw-flac tracking bugs for this issue:

Affects: fedora-all [bug 1169699]

Comment 4 Francisco Alonso 2014-12-02 09:00:55 UTC
Created xmms-flac tracking bugs for this issue:

Affects: fedora-all [bug 1169700]

Comment 5 Francisco Alonso 2014-12-02 09:00:58 UTC
Created flac tracking bugs for this issue:

Affects: fedora-all [bug 1169698]

Comment 6 Fedora Update System 2014-12-07 04:34:06 UTC
flac-1.3.1-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2014-12-13 09:41:27 UTC
flac-1.3.1-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2014-12-13 09:55:06 UTC
mingw-flac-1.3.1-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2014-12-13 09:55:21 UTC
mingw-flac-1.3.1-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2014-12-13 09:56:41 UTC
mingw-flac-1.3.1-1.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2014-12-17 19:43:52 UTC
mingw-flac-1.3.1-1.el7 has been pushed to the Fedora EPEL 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2014-12-20 08:45:26 UTC
flac-1.3.1-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 15 errata-xmlrpc 2015-04-01 03:34:31 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7
  Red Hat Enterprise Linux 6

Via RHSA-2015:0767 https://rhn.redhat.com/errata/RHSA-2015-0767.html

Comment 16 Fedora Update System 2015-08-15 02:21:42 UTC
flac-1.3.1-5.fc22 has been pushed to the Fedora 22 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 17 Fedora Update System 2015-08-18 05:22:39 UTC
flac-1.3.1-5.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 18 Fedora Update System 2015-08-18 05:25:58 UTC
flac-1.3.1-5.fc23 has been pushed to the Fedora 23 stable repository.  If problems still persist, please make note of it in this bug report.