Risk | High |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2017-11720 |
CWE-ID | CWE-369 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
lame (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU33254
Risk: High
CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2017-11720
CWE-ID:
CWE-369 - Divide By Zero
Exploit availability: No
DescriptionThe vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
MitigationInstall update from vendor's website.
Vulnerable software versionslame (Alpine package): 3.99.5-r0 - 3.99.5-r5
CPE2.3http://git.alpinelinux.org/aports/commit/?id=1900edcab539a7ab32e3ad868597f7358fa798ad
http://git.alpinelinux.org/aports/commit/?id=22711d8124dcf1724b3b0ae900bf89567c5b979a
http://git.alpinelinux.org/aports/commit/?id=7f60893b079de3f360f2d63a76079f32a019f042
http://git.alpinelinux.org/aports/commit/?id=c6826747b05fd69a8385c80f7ba19d2260dd32ba
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.