CVE-2017-6836
published 2017-03-20CVE-2017-6836: Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
2.87%
85.2th percentile
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| audiofile | audiofile | — | — |
| audiofile | audiofile | >= 0 < 0.3.6-4 | 0.3.6-4 |
| audiofile | audiofile | >= 0 < 0.3.6-4 | 0.3.6-4 |
| audiofile | audiofile | >= 0 < 0.3.6-4 | 0.3.6-4 |
| audiofile | audiofile | >= 0 < 0.3.6-4 | 0.3.6-4 |
| debian | audiofile | < audiofile 0.3.6-4 (bookworm) | audiofile 0.3.6-4 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| msrc | cbl2_audiofile_0.3.6-27_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
audiofile vulnerabilities
vendor_ubuntu·2017-03-22
CVE-2017-6827 audiofile vulnerabilities
Title: audiofile vulnerabilities
Summary: audiofile could be made to crash or run programs if it opened a specially
crafted file.
Agostino Sarubbo discovered that audiofile incorrectly handled certain
malformed audio files. If a user or automated system were tricked into
processing a specially crafted audio file, a remote attacker could cause
applications linked against audiofile to crash, leading to a denial of
service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows rem
vendor_msrc·2017-03-14·CVSS 5.5
CVE-2017-6836 [MEDIUM] CWE-119 Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows rem
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more informati
Red Hat
audiofile: Heap-based buffer overflow in Expand3To4Module::run
vendor_redhat·2017-02-26·CVSS 5.5
CVE-2017-6836 [MEDIUM] CWE-122 audiofile: Heap-based buffer overflow in Expand3To4Module::run
audiofile: Heap-based buffer overflow in Expand3To4Module::run
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.
Package: audiofile (Red Hat Enterprise Linux 5) - Will not fix
Package: audiofile (Red Hat Enterprise Linux 6) - Will not fix
Package: audiofile (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-6836: audiofile - Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile...
vendor_debian·2017·CVSS 5.5
CVE-2017-6836 [MEDIUM] CVE-2017-6836: audiofile - Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile...
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.
Scope: local
bookworm: resolved (fixed in 0.3.6-4)
bullseye: resolved (fixed in 0.3.6-4)
forky: resolved (fixed in 0.3.6-4)
sid: resolved (fixed in 0.3.6-4)
trixie: resolved (fixed in 0.3.6-4)
GHSA
GHSA-2jmf-7qjf-v556: Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule
ghsa_unreviewed·2022-05-13
CVE-2017-6836 [MEDIUM] CWE-119 GHSA-2jmf-7qjf-v556: Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.
OSV
CVE-2017-6836: Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule
osv·2017-03-20·CVSS 5.5
CVE-2017-6836 [MEDIUM] CVE-2017-6836: Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833 CVE-2017-6834 CVE-2017-6836 CVE-2017-6835 CVE-2017-6837 CVE-2017-6838 CVE-2017-6839 audiofile: various
bugzilla·2017-03-16·CVSS 7.8
CVE-2017-6827 [HIGH] CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833 CVE-2017-6834 CVE-2017-6836 CVE-2017-6835 CVE-2017-6837 CVE-2017-6838 CVE-2017-6839 audiofile: various
CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830 CVE-2017-6831 CVE-2017-6832 CVE-2017-6833 CVE-2017-6834 CVE-2017-6836 CVE-2017-6835 CVE-2017-6837 CVE-2017-6838 CVE-2017-6839 audiofile: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please
Bugzilla
CVE-2017-6836 audiofile: Heap-based buffer overflow in Expand3To4Module::run
bugzilla·2017-03-16·CVSS 5.5
CVE-2017-6836 [MEDIUM] CVE-2017-6836 audiofile: Heap-based buffer overflow in Expand3To4Module::run
CVE-2017-6836 audiofile: Heap-based buffer overflow in Expand3To4Module::run
A heap buffer overflow vulnerability was found in audiofile. Opening a maliciously crafted file could cause the application to crash.
References:
http://seclists.org/oss-sec/2017/q1/513
Discussion:
Created audiofile tracking bugs for this issue:
Affects: fedora-all [bug 1432945]
http://www.debian.org/security/2017/dsa-3814http://www.openwall.com/lists/oss-security/2017/03/13/8https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-expand3to4modulerun-simplemodule-h/https://github.com/mpruett/audiofile/issues/40https://github.com/mpruett/audiofile/pull/42http://www.debian.org/security/2017/dsa-3814http://www.openwall.com/lists/oss-security/2017/03/13/8https://blogs.gentoo.org/ago/2017/02/20/audiofile-heap-based-buffer-overflow-in-expand3to4modulerun-simplemodule-h/https://github.com/mpruett/audiofile/issues/40https://github.com/mpruett/audiofile/pull/42
2017-03-20
Published