PT-2017-14852 · Aubio+1 · Aubio+1
Published
2017-12-12
·
Updated
2022-05-14
·
CVE-2017-17554
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
aubio version 0.4.6
Description
A NULL pointer dereference issue was found in the
aubio source avcodec readframe function, which may lead to a denial of service (DoS) when playing a crafted audio file. This issue is related to the file io/source avcodec.c.Recommendations
For aubio version 0.4.6, consider disabling the
aubio source avcodec readframe function until a patch is available to prevent potential DoS attacks when playing crafted audio files.Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Aubio