CVE-2017-6829Out-of-bounds Read in Audiofile

Severity
5.5MEDIUMNVD
EPSS
4.6%
top 10.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 13

Description

The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/audiofile< audiofile 0.3.6-4 (bookworm)
Debianaudiofile/audiofile< 0.3.6-4+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4346-2577-gf85: The decodeSample function in IMA2022-05-13
OSV
CVE-2017-6829: The decodeSample function in IMA2017-03-20

📋Vendor Advisories

4
Ubuntu
audiofile vulnerabilities2017-03-22
Microsoft
The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.2017-03-14
Red Hat
audiofile: Global buffer overflow in decodeSample2017-02-26
Debian
CVE-2017-6829: audiofile - The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6...2017

💬Community

2
Bugzilla
CVE-2017-6829 audiofile: Global buffer overflow in decodeSample2017-03-16
Bugzilla
CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833 CVE-2017-6834 CVE-2017-6836 CVE-2017-6835 CVE-2017-6837 CVE-2017-6838 CVE-2017-6839 audiofile: various2017-03-16