CVE-2017-18201
published 2018-02-26CVE-2017-18201: An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
PriorityP340critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.30%
87.1th percentile
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libcdio | < libcdio 2.0.0-2 (bookworm) | libcdio 2.0.0-2 (bookworm) |
| gnu | libcdio | < 2.0.0 | 2.0.0 |
| gnu | libcdio | >= 0 < 2.0.0-2 | 2.0.0-2 |
| gnu | libcdio | >= 0 < 2.0.0-2 | 2.0.0-2 |
| gnu | libcdio | >= 0 < 2.0.0-2 | 2.0.0-2 |
| gnu | libcdio | >= 0 < 2.0.0-2 | 2.0.0-2 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8qcw-8m67-996h: An issue was discovered in GNU libcdio before 2
ghsa_unreviewed·2022-05-14
CVE-2017-18201 [CRITICAL] CWE-415 GHSA-8qcw-8m67-996h: An issue was discovered in GNU libcdio before 2
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
OSV
CVE-2017-18201: An issue was discovered in GNU libcdio before 2
osv·2018-02-26·CVSS 9.8
CVE-2017-18201 [CRITICAL] CVE-2017-18201: An issue was discovered in GNU libcdio before 2
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
Red Hat
libcdio: Double free in get_cdtext_generic() in lib/driver/_cdio_generic.c
vendor_redhat·2018-02-27·CVSS 9.8
CVE-2017-18201 [CRITICAL] CWE-119 libcdio: Double free in get_cdtext_generic() in lib/driver/_cdio_generic.c
libcdio: Double free in get_cdtext_generic() in lib/driver/_cdio_generic.c
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
A double-free flaw was found in the way libcdio handled processing of ISO files. An attacker could potentially use this flaw to crash applications using libcdio by tricking them into processing crafted ISO files.
Package: libcdio (Red Hat Enterprise Linux 6) - Not affected
Package: libcdio (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2017-18201: libcdio - An issue was discovered in GNU libcdio before 2.0.0. There is a double free in g...
vendor_debian·2017·CVSS 9.8
CVE-2017-18201 [CRITICAL] CVE-2017-18201: libcdio - An issue was discovered in GNU libcdio before 2.0.0. There is a double free in g...
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
Scope: local
bookworm: resolved (fixed in 2.0.0-2)
bullseye: resolved (fixed in 2.0.0-2)
forky: resolved (fixed in 2.0.0-2)
sid: resolved (fixed in 2.0.0-2)
trixie: resolved (fixed in 2.0.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-18198 CVE-2017-18199 CVE-2017-18201 libcdio: various flaws [fedora-all]
bugzilla·2018-02-27·CVSS 8.8
CVE-2017-18198 [HIGH] CVE-2017-18198 CVE-2017-18199 CVE-2017-18201 libcdio: various flaws [fedora-all]
CVE-2017-18198 CVE-2017-18199 CVE-2017-18201 libcdio: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2017-18201 libcdio: Double free in get_cdtext_generic() in lib/driver/_cdio_generic.c
bugzilla·2018-02-27·CVSS 9.8
CVE-2017-18201 [CRITICAL] CVE-2017-18201 libcdio: Double free in get_cdtext_generic() in lib/driver/_cdio_generic.c
CVE-2017-18201 libcdio: Double free in get_cdtext_generic() in lib/driver/_cdio_generic.c
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
Upstream patch:
https://git.savannah.gnu.org/cgit/libcdio.git/commit/?id=dec2f876c2d7162da213429bce1a7140cdbdd734
External References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887640
Discussion:
Created libcdio tracking bugs for this issue:
Affects: fedora-all [bug 1549713]
---
I am trying to understand the this bug tracking system.
When I read:
> Affects: fedora-all [bug 1549713]
What does "fedora-all" mean? As noted previously, the bug was introduced sometime after 0.90 (definitely in 0.94) but fixed in 2.0.0
---
I understand 'fedora-all' as all a
http://www.securityfocus.com/bid/103190https://access.redhat.com/errata/RHSA-2018:3246https://git.savannah.gnu.org/cgit/libcdio.git/commit/?id=f6f9c48fb40b8a1e8218799724b0b61a7161eb1dhttp://www.securityfocus.com/bid/103190https://access.redhat.com/errata/RHSA-2018:3246https://git.savannah.gnu.org/cgit/libcdio.git/commit/?id=f6f9c48fb40b8a1e8218799724b0b61a7161eb1d
2018-02-26
Published