Out-of-bounds read in libsndfile - CVE-2017-17456

 

Out-of-bounds read in libsndfile - CVE-2017-17456

Published: March 5, 2018 / Updated: March 20, 2018


Vulnerability identifier: #VU10832
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17456
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists in the d2alaw_array() function due to out-of-bounds read. A remote attacker can create a specially crafted source code, trick the victim into opening it, trigger memory corruption and to cause the service to crash.

Affected software

libsndfile
libsndfile (Ubuntu package)
libsndfile (Alpine package)
Opensuse

How to mitigate CVE-2017-17456

Cybersecurity is currently unaware of any solutions addressing the vulnerability.

libsndfile (Ubuntu package) - addressed in versions 1.0.25-10ubuntu0.16.04.2, 1.0.28-4ubuntu0.18.04.1, 1.0.28-4ubuntu0.18.10.1
libsndfile (Alpine package) - update to 1.0.28-r4

External References

Related Security Bulletins