A flaw was found in libao. The _tokenize_matrix function in audio_out.c
in Xiph.Org libao 1.2.0 can cause a denial of service(memory corruption)
via a crafted mp3 file (CVE-2017-11548).
- https://bugs.mageia.org/show_bug.cgi?id=23402
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/LIZBEBMU7CW7K7KQ53E4OPSRTR6DZRNO/
- https://www.cve.org/CVERecord?id=CVE-2017-11548
- 6/core/libao-1.2.2-3.1.mga6
Get the latest Linux and open source security news straight to your inbox.