Menu

#460 A division by zero vulnerability

Usability
closed
5
2017-08-13
2017-07-26
WangShiyang
No

Overview:

I discovered an division by zero vulnerability in lame, which is caused by mal-constructed input file using American Fuzzy Loop.

Report and POC:

The detail analysis report and PoC files can be found in the attachment. In order to avoid disclosing it before release of patch, I have encrypted the zip file. Developers can communicate with me to get the password.

Author

name: Shiyang,Wang @ VARAS of IIE ,Bingchang, Liu @ VARAS of IIE
email: wangshiyang@iie.ac.cn
org: IIE (http://iie.ac.cn)

1 Attachments

Discussion

  • WangShiyang

    WangShiyang - 2017-07-28

    this bug has been sigend CVE-2017-11720.

     
  • WangShiyang

    WangShiyang - 2017-08-06

    the password of the poc file is $12a461oxxp1o$@autgnaw

     

    Last edit: WangShiyang 2017-08-06
  • Robert Hegemann

    Robert Hegemann - 2017-08-13
    • status: open --> closed
    • assigned_to: Robert Hegemann
     
  • Robert Hegemann

    Robert Hegemann - 2017-08-13

    Thanks, it will be fixed in version 3.100.

     

Log in to post a comment.