Related Vulnerabilities: CVE-2017-6837  

Integer overflow triggering an assertion on the WAVE module using sfconvert.

Severity Medium

Remote No

Type Denial of service

Description

Integer overflow triggering an assertion on the WAVE module using sfconvert.

AVG-205 audiofile 0.3.6-3 0.3.6-4 High Fixed

14 Aug 2017 ASA-201708-9 AVG-205 audiofile High multiple issues

https://blogs.gentoo.org/ago/2017/02/20/audiofile-multiple-ubsan-crashes/