CVE-2017-6829 — Out-of-bounds Read in Audiofile
Severity
5.5MEDIUMNVD
EPSS
4.6%
top 10.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 20
Latest updateMay 13
Description
The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
4Microsoft▶
The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.↗2017-03-14
Debian▶
CVE-2017-6829: audiofile - The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6...↗2017
💬Community
2Bugzilla▶
CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833 CVE-2017-6834 CVE-2017-6836 CVE-2017-6835 CVE-2017-6837 CVE-2017-6838 CVE-2017-6839 audiofile: various↗2017-03-16