Out-of-bounds read in libsamplerate - CVE-2017-7697
Published: April 12, 2017 / Updated: July 28, 2020
Vulnerability identifier: #VU32093
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7697
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
Affected software
libsamplerate
libsamplerate (Alpine package)
libsamplerate0 (Ubuntu package)
libsamplerate
IBM Tivoli Storage Manager
Ubuntu
Fedora
libsamplerate (Alpine package)
libsamplerate0 (Ubuntu package)
libsamplerate
IBM Tivoli Storage Manager
Ubuntu
Fedora
How to mitigate CVE-2017-7697
Install update from vendor's website.
libsamplerate - update to 0.1.9
libsamplerate (Alpine package) - update to 0.1.9-r0
libsamplerate0 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libsamplerate - addressed in versions 0.1.9-1.fc26, 0.1.9-1.fc27
libsamplerate (Alpine package) - update to 0.1.9-r0
libsamplerate0 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libsamplerate - addressed in versions 0.1.9-1.fc26, 0.1.9-1.fc27