PT-2017-18290 · Eric Youngdale+3 · Libsndfile+3

Agostino Sarubbo

·

Published

2017-04-30

·

Updated

2021-07-05

·

CVE-2017-8363

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsndfile version 1.0.28
Description The issue allows remote attackers to cause a denial of service, resulting in a heap-based buffer over-read and application crash, via a crafted audio file. This is due to a problem in the flac buffer copy function in flac.c.
Recommendations For libsndfile version 1.0.28, consider avoiding the use of crafted audio files until a patch is available. As a temporary workaround, restrict the processing of audio files from untrusted sources to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3449
ALT-PU-2020-3469
ALT-PU-2021-2149
CVE-2017-8363
DLA-1618-1
DLA-956-1
MGASA-2017-0168
SUSE-SU-2017:1236-1
SUSE-SU-2017:1367-1
USN-3306-1

Affected Products

Alt Linux
Suse
Ubuntu
Libsndfile