PT-2017-14687 · Aubio · Aubio

My123Pxo

·

Publicado

2017-11-29

·

Atualizado

2022-05-17

·

CVE-2017-17054

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions aubio version 0.4.6
Description A divide-by-zero error exists in the function new aubio source wavread() in source wavread.c, which may lead to Denial of Service (DoS) when playing a crafted audio file.
Recommendations For aubio version 0.4.6, consider disabling the new aubio source wavread() function until a patch is available to prevent potential DoS attacks when playing crafted audio files.

Correção

Divide By Zero

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17054
GHSA-VCWX-8MQH-2557
MGASA-2018-0194
OPENSUSE-SU-2024:10638-1
PYSEC-2017-75

Produtos afetados

Aubio