UBUNTU-CVE-2017-6888

Source
https://ubuntu.com/security/CVE-2017-6888
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-6888.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-6888
Related
Published
2018-04-25T21:29:00Z
Modified
2024-10-15T14:06:16Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An error in the "readmetadatavorbiscomment()" function (src/libFLAC/streamdecoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.

References

Affected packages

Ubuntu:Pro:14.04:LTS / flac

Package

Name
flac
Purl
pkg:deb/ubuntu/flac?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.0-2ubuntu0.14.04.1+esm1

Affected versions

1.*

1.3.0-1
1.3.0-2
1.3.0-2ubuntu0.14.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "flac"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "flac-dbgsym"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "libflac++-dev"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "libflac++6"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "libflac++6-dbgsym"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "libflac-dev"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "libflac-doc"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "libflac8"
        },
        {
            "binary_version": "1.3.0-2ubuntu0.14.04.1+esm1",
            "binary_name": "libflac8-dbgsym"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / flac

Package

Name
flac
Purl
pkg:deb/ubuntu/flac?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.1-4ubuntu0.1~esm1

Affected versions

1.*

1.3.1-4

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.3.1-4ubuntu0.1~esm1",
            "binary_name": "flac"
        },
        {
            "binary_version": "1.3.1-4ubuntu0.1~esm1",
            "binary_name": "libflac++-dev"
        },
        {
            "binary_version": "1.3.1-4ubuntu0.1~esm1",
            "binary_name": "libflac++6v5"
        },
        {
            "binary_version": "1.3.1-4ubuntu0.1~esm1",
            "binary_name": "libflac++6v5-dbgsym"
        },
        {
            "binary_version": "1.3.1-4ubuntu0.1~esm1",
            "binary_name": "libflac-dev"
        },
        {
            "binary_version": "1.3.1-4ubuntu0.1~esm1",
            "binary_name": "libflac-doc"
        },
        {
            "binary_version": "1.3.1-4ubuntu0.1~esm1",
            "binary_name": "libflac8"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / oxide-qt

Package

Name
oxide-qt
Purl
pkg:deb/ubuntu/oxide-qt?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.9.5-0ubuntu1
1.10.3-0ubuntu0.15.10.1
1.10.3-0ubuntu0.15.10.2
1.11.3-0ubuntu3
1.11.4-0ubuntu1
1.11.5-0ubuntu1
1.12.5-0ubuntu1
1.12.6-0ubuntu1
1.12.7-0ubuntu1
1.13.6-0ubuntu1
1.14.7-0ubuntu1
1.14.9-0ubuntu0.16.04.1
1.15.7-0ubuntu0.16.04.1
1.15.8-0ubuntu0.16.04.1
1.16.5-0ubuntu0.16.04.1
1.17.7-0ubuntu0.16.04.1
1.17.9-0ubuntu0.16.04.1
1.18.3-0ubuntu0.16.04.1
1.18.5-0ubuntu0.16.04.1
1.19.4-0ubuntu0.16.04.1
1.20.4-0ubuntu0.16.04.1
1.21.5-0ubuntu0.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:16.04:LTS / android

Package

Name
android
Purl
pkg:deb/ubuntu/android?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

20150818-1500-0ubuntu2
20150818-1500-0ubuntu3
20160307-0742-0ubuntu3
20160330-0939-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:16.04:LTS / praat

Package

Name
praat
Purl
pkg:deb/ubuntu/praat?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.3.16-1ubuntu2

6.*

6.0.4-2ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:18.04:LTS / flac

Package

Name
flac
Purl
pkg:deb/ubuntu/flac?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.2-1ubuntu0.1

Affected versions

1.*

1.3.2-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "flac"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "flac-dbgsym"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "libflac++-dev"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "libflac++6v5"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "libflac++6v5-dbgsym"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "libflac-dev"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "libflac-doc"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "libflac8"
        },
        {
            "binary_version": "1.3.2-1ubuntu0.1",
            "binary_name": "libflac8-dbgsym"
        }
    ]
}

Ubuntu:Pro:18.04:LTS / praat

Package

Name
praat
Purl
pkg:deb/ubuntu/praat?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.0.30-3
6.0.37-2

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:20.04:LTS / flac

Package

Name
flac
Purl
pkg:deb/ubuntu/flac?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-1build1

Affected versions

1.*

1.3.3-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "flac"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "flac-dbgsym"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "libflac++-dev"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "libflac++6v5"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "libflac++6v5-dbgsym"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "libflac-dev"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "libflac-doc"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "libflac8"
        },
        {
            "binary_version": "1.3.3-1build1",
            "binary_name": "libflac8-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / praat

Package

Name
praat
Purl
pkg:deb/ubuntu/praat?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1-1
6.1.05-2
6.1.09-1
6.1.09-1build1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:22.04:LTS / flac

Package

Name
flac
Purl
pkg:deb/ubuntu/flac?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.3-2build2

Affected versions

1.*

1.3.3-2
1.3.3-2build1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "flac"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "flac-dbgsym"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "libflac++-dev"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "libflac++6v5"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "libflac++6v5-dbgsym"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "libflac-dev"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "libflac-doc"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "libflac8"
        },
        {
            "binary_version": "1.3.3-2build2",
            "binary_name": "libflac8-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / praat

Package

Name
praat
Purl
pkg:deb/ubuntu/praat?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.1.38-1
6.1.56-1
6.1.56-2
6.2.01-1
6.2.03-1
6.2.04-1
6.2.05-1
6.2.06-1
6.2.07-1
6.2.09-1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:24.10 / praat

Package

Name
praat
Purl
pkg:deb/ubuntu/praat?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.4.06+dfsg-1build2
6.4.12+dfsg-3

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:24.04:LTS / praat

Package

Name
praat
Purl
pkg:deb/ubuntu/praat?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.3.14-1
6.4.05+dfsg-1
6.4.06+dfsg-1build1
6.4.06+dfsg-1build2

Ecosystem specific

{
    "ubuntu_priority": "low"
}