CVE Vulnerabilities

CVE-2017-11549

Excessive Iteration

Published: Jul 31, 2017 | Modified: Oct 03, 2019
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
7.1 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The play_midi function in playmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mid file. NOTE: CPU consumption might be relevant when using the –background option.

Weakness

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

Affected Software

Name Vendor Start Version End Version
Timidity++ Timidity++_project 2.14.0 (including) 2.14.0 (including)
Timidity Ubuntu artful *
Timidity Ubuntu bionic *
Timidity Ubuntu cosmic *
Timidity Ubuntu devel *
Timidity Ubuntu disco *
Timidity Ubuntu eoan *
Timidity Ubuntu esm-apps/bionic *
Timidity Ubuntu esm-apps/focal *
Timidity Ubuntu esm-apps/jammy *
Timidity Ubuntu esm-apps/noble *
Timidity Ubuntu esm-apps/xenial *
Timidity Ubuntu focal *
Timidity Ubuntu groovy *
Timidity Ubuntu hirsute *
Timidity Ubuntu impish *
Timidity Ubuntu jammy *
Timidity Ubuntu kinetic *
Timidity Ubuntu lunar *
Timidity Ubuntu mantic *
Timidity Ubuntu noble *
Timidity Ubuntu oracular *
Timidity Ubuntu trusty *
Timidity Ubuntu upstream *
Timidity Ubuntu xenial *
Timidity Ubuntu zesty *

References