Out-of-bounds read in libsndfile - CVE-2017-17456
Published: March 5, 2018 / Updated: March 20, 2018
Vulnerability identifier: #VU10832
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17456
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the d2alaw_array() function due to out-of-bounds read. A remote attacker can create a specially crafted source code, trick the victim into opening it, trigger memory corruption and to cause the service to crash.
The weakness exists in the d2alaw_array() function due to out-of-bounds read. A remote attacker can create a specially crafted source code, trick the victim into opening it, trigger memory corruption and to cause the service to crash.
Affected software
libsndfile
libsndfile (Ubuntu package)
libsndfile (Alpine package)
Opensuse
libsndfile (Ubuntu package)
libsndfile (Alpine package)
Opensuse
How to mitigate CVE-2017-17456
Cybersecurity is currently unaware of any solutions addressing the vulnerability.
libsndfile (Ubuntu package) - addressed in versions 1.0.25-10ubuntu0.16.04.2, 1.0.28-4ubuntu0.18.04.1, 1.0.28-4ubuntu0.18.10.1
libsndfile (Alpine package) - update to 1.0.28-r4
libsndfile (Alpine package) - update to 1.0.28-r4