CVE-2017-6827Improper Restriction of Operations within the Bounds of a Memory Buffer in Audiofile

Severity
7.8HIGHNVD
EPSS
33.8%
top 3.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 17

Description

Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted audio file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/audiofile< audiofile 0.3.6-4 (bookworm)
Debianaudiofile/audiofile< 0.3.6-4+3

🔴Vulnerability Details

2
GHSA
GHSA-wqjg-fvmh-6mj6: Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM2022-05-17
OSV
CVE-2017-6827: Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM2017-03-15

📋Vendor Advisories

4
Ubuntu
audiofile vulnerabilities2017-03-22
Microsoft
Heap-based buffer overflow in audiofile allows remote attackers to have unspecified impact via a crafted audio file2017-03-14
Red Hat
audiofile: Heap-based buffer overflow in MSADPCM::initializeCoefficients2017-02-26
Debian
CVE-2017-6827: audiofile - Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MS...2017

💬Community

2
Bugzilla
CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833 CVE-2017-6834 CVE-2017-6836 CVE-2017-6835 CVE-2017-6837 CVE-2017-6838 CVE-2017-6839 audiofile: various2017-03-16
Bugzilla
CVE-2017-6827 audiofile: Heap-based buffer overflow in MSADPCM::initializeCoefficients2017-03-16