Severity
8.8HIGHNVD
EPSS
54.0%
top 1.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 24

Description

Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

debiandebian/audiofile< audiofile 0.3.6-3 (bookworm)
NVDaudiofile/audiofile< 0.3.6
Debianaudiofile/audiofile< 0.3.6-3+3

Also affects: Fedora 23, Ubuntu Linux 12.04, 14.04, 15.04, 15.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-87hr-6cw6-rj3c: Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a d2022-05-24
OSV
CVE-2015-7747: Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a d2020-02-19

📋Vendor Advisories

4
Microsoft
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execu2020-02-11
Ubuntu
audiofile vulnerability2015-10-28
Red Hat
audiofile: Buffer overflow when changing number of channels and sample format2015-10-04
Debian
CVE-2015-7747: audiofile - Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and ...2015

💬Community

2
Bugzilla
CVE-2015-7747 audiofile: Buffer overflow when changing number of channels and sample format2015-10-08
Bugzilla
CVE-2015-7747 audiofile: Buffer overflow when changing number of channels and sample format [fedora-all]2015-10-08