Bug 1923891 (CVE-2017-1000010)

Summary: CVE-2017-1000010 audacity: dll hijacking in avformat-55.dll resulting arbitrary code execution
Product: [Other] Security Response Reporter: Dhananjay Arunesh <darunesh>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dtimms, gemi, ian.s.mcinerney, manpaz, moez.roy
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-28 05:29:06 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dhananjay Arunesh 2021-02-02 07:15:42 UTC
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.

References:
https://github.com/GitHubAssessments/CVE_Assessments_10_2019
https://packetstormsecurity.com/files/140365/Audacity-2.1.2-DLL-Hijacking.html

Comment 1 Ian McInerney 2021-02-02 17:32:07 UTC
The referenced disclosure thread seems to suggest that only the Windows version of Audacity is susceptible to this - so is this really an actionable CVE for the Linux packages? (yes, I realize I need to update the package anyway to get to the recent version - but upstream politics has annoyed me recently so I haven't had the bandwidth to do that yet). Basically my question is this: what is the attack surface on the Linux package for this?