Out-of-bound read in libsndfile - CVE-2017-17457
Published: March 5, 2018 / Updated: March 20, 2018
Vulnerability identifier: #VU10834
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17457
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists in the d2ulaw_array() function due to out-of-bounds read. A remote attacker send a specially crafted input, trigger memory corruption and cause the service to crash.
The weakness exists in the d2ulaw_array() function due to out-of-bounds read. A remote attacker send a specially crafted input, trigger memory corruption and cause the service to crash.
Affected software
libsndfile
libsndfile (Ubuntu package)
libsndfile (Alpine package)
Opensuse
libsndfile (Ubuntu package)
libsndfile (Alpine package)
Opensuse
How to mitigate CVE-2017-17457
Cybersecurity is currently unaware of any solutions addressing the vulnerability.
libsndfile (Ubuntu package) - addressed in versions 1.0.25-10ubuntu0.16.04.2, 1.0.28-4ubuntu0.18.04.1, 1.0.28-4ubuntu0.18.10.1
libsndfile (Alpine package) - update to 1.0.28-r4
libsndfile (Alpine package) - update to 1.0.28-r4