CVE-2017-7697
published 2017-04-11CVE-2017-7697: In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
PriorityP416medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.91%
56.8th percentile
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libsamplerate | < libsamplerate 0.1.9-1 (bookworm) | libsamplerate 0.1.9-1 (bookworm) |
| libsamplerate_project | libsamplerate | <= 0.1.8 | — |
| libsamplerate_project | libsamplerate | >= 0 < 0.1.9-1 | 0.1.9-1 |
| libsamplerate_project | libsamplerate | >= 0 < 0.1.9-1 | 0.1.9-1 |
| libsamplerate_project | libsamplerate | >= 0 < 0.1.9-1 | 0.1.9-1 |
| libsamplerate_project | libsamplerate | >= 0 < 0.1.9-1 | 0.1.9-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qm8v-gjcq-7m6j: In libsamplerate before 0
ghsa_unreviewed·2022-05-13
CVE-2017-7697 [MEDIUM] CWE-125 GHSA-qm8v-gjcq-7m6j: In libsamplerate before 0
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
OSV
CVE-2017-7697: In libsamplerate before 0
osv·2017-04-11·CVSS 5.5
CVE-2017-7697 [MEDIUM] CVE-2017-7697: In libsamplerate before 0
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
Ubuntu
libsamplerate vulnerability
vendor_ubuntu·2022-11-29
CVE-2017-7697 libsamplerate vulnerability
Title: libsamplerate vulnerability
Summary: libsamplerate could cause a crash if it processed a specially crafted
audio file.
Erik de Castro Lopo and Agostino Sarubbo discovered that libsamplerate
did not properly perform bounds checking. If a user were tricked into
processing a specially crafted audio file, an attacker could possibly
use this issue to cause a crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libsamplerate: Buffer overflow in calc_output_single
vendor_redhat·2017-04-11·CVSS 5.5
CVE-2017-7697 [MEDIUM] CWE-119 libsamplerate: Buffer overflow in calc_output_single
libsamplerate: Buffer overflow in calc_output_single
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
Package: libsamplerate (Red Hat Enterprise Linux 6) - Will not fix
Package: libsamplerate (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-7697: libsamplerate - In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_sing...
vendor_debian·2017·CVSS 5.5
CVE-2017-7697 [MEDIUM] CVE-2017-7697: libsamplerate - In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_sing...
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
Scope: local
bookworm: resolved (fixed in 0.1.9-1)
bullseye: resolved (fixed in 0.1.9-1)
forky: resolved (fixed in 0.1.9-1)
sid: resolved (fixed in 0.1.9-1)
trixie: resolved (fixed in 0.1.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all]
bugzilla·2017-04-12·CVSS 5.5
CVE-2017-7697 [MEDIUM] CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all]
CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versio
Bugzilla
CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single
bugzilla·2017-04-12·CVSS 5.5
CVE-2017-7697 [MEDIUM] CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single
CVE-2017-7697 libsamplerate: Buffer overflow in calc_output_single
A buffer overflow vulnerability was found in libsamplerate. A maliciously crafted audio file could cause the application to crash.
Upstream bug:
https://github.com/erikd/libsamplerate/issues/11
Discussion:
Created libsamplerate tracking bugs for this issue:
Affects: fedora-all [bug 1441644]
http://www.securityfocus.com/bid/97587https://github.com/erikd/libsamplerate/issues/11https://lists.debian.org/debian-lts-announce/2021/12/msg00010.htmlhttp://www.securityfocus.com/bid/97587https://github.com/erikd/libsamplerate/issues/11https://lists.debian.org/debian-lts-announce/2021/12/msg00010.html
2017-04-11
Published